Live data from Hacker News

Microsoft Can't Keep EU Data Safe from US Authorities

forbes.com

91–100 of 136 posts

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#91
post #60

This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply. "I will never give up customer data" is a very tough promise to keep, if the government threatens you with your business license being revoked, your servers and domains being forcibly seized by the police, and you personally going to jail. (Under the current US administration, we can add "A close examin…

Well yes but that is all the more reason for EU entities to use EU companies for data storage.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#92

> Carniaux did say that the situation had never arisen. That's what he would say if the company was under a gag order in the US. So I would take anything they say with a mountain of salt.

Specifically here, he is under oath in France so an American gag order wouldn't protect him from the French justice system. This make it less likely he's lying. It could be possible Microsoft France has a "rogue" employee system where a key person only obeys to Microsoft US orders rather than his French boss and French law. Then the boss can swear to the Senate that they're complying. This is exactly the system the U…

> This make it less likely he's lying. It could be possible Microsoft France has a "rogue" employee system where a key person only obeys to Microsoft US orders rather than his French boss and French law. Then the boss can swear to the Senate that they're complying.

It's also possible that US employees had access to French servers without anyone in France knowing.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#93
post #60

This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply. "I will never give up customer data" is a very tough promise to keep, if the government threatens you with your business license being revoked, your servers and domains being forcibly seized by the police, and you personally going to jail. (Under the current US administration, we can add "A close examin…

> This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply.

Not all countries have an equivalent to the USA CLOUD Act.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#95

Maybe I’m misunderstanding something - if I store my data elsewhere , am I not supposed to encrypt it anyway, with my keys ? If the crypto is strong enough then surely cloud providers can’t do anything with it ?

> Maybe I’m misunderstanding something - if I store my data elsewhere , am I not supposed to encrypt it anyway

"Cloud" is not only for storage; it's also for compute. Doing compute directly on encrypted data (homomorphic encryption) is very slow and very complicated, so when using a cloud, the data is usually either unencrypted, or encrypted but the key is elsewhere in the same cloud.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#96
post #48

This is known. The problem is that the EU is hooked on us technology. I don’t see this untangling soon which is a big strategic weakness

Pretty much yes. From Saas to authentication systems to OS to chips. The EU infra is entirely dependent on the US. All documents, emails, chat messages, and most forms of storage are directly or indirectly linked to an American service. On top of that, the US can update it all remotely, including the hardware now thanks to things like intel ME. Let's hope we never get into a conflict with them, because even without b…

> the US can update it all remotely, including the hardware now thanks to things like intel ME

Let's not be excessively alarmist; AFAIK, the Intel ME is not (unless you're using things like vPro) exposed directly to the network, you need the cooperation of the operating system to reach the ME.

Of course, said operating system is usually Microsoft Windows, which can be updated remotely... (and even Linux users often use USA-based distributions).

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#97
post #96

Earlier quoted context omitted.

Pretty much yes. From Saas to authentication systems to OS to chips. The EU infra is entirely dependent on the US. All documents, emails, chat messages, and most forms of storage are directly or indirectly linked to an American service. On top of that, the US can update it all remotely, including the hardware now thanks to things like intel ME. Let's hope we never get into a conflict with them, because even without b…

> the US can update it all remotely, including the hardware now thanks to things like intel ME Let's not be excessively alarmist; AFAIK, the Intel ME is not (unless you're using things like vPro) exposed directly to the network, you need the cooperation of the operating system to reach the ME. Of course, said operating system is usually Microsoft Windows, which can be updated remotely... (and even Linux users often u…

According to its specs, but since it's a black box for which we have neither the source nor the design documents, and given that implementing back doors is a regular request from governments, it's a logical concern.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#98
post #95

Maybe I’m misunderstanding something - if I store my data elsewhere , am I not supposed to encrypt it anyway, with my keys ? If the crypto is strong enough then surely cloud providers can’t do anything with it ?

> Maybe I’m misunderstanding something - if I store my data elsewhere , am I not supposed to encrypt it anyway "Cloud" is not only for storage; it's also for compute. Doing compute directly on encrypted data (homomorphic encryption) is very slow and very complicated, so when using a cloud, the data is usually either unencrypted, or encrypted but the key is elsewhere in the same cloud.

Thanks.

I get that FHE is not realistic today, but can’t I use ( if it’s really critical) a combination of confidential vms and an external hsm ? I understand I’ll be limited to traditional workloads , and not managed services though.

I asked the wrong question, what I really meant was ‘if I run in a less trusted environment, am I not supposed to use all possible crypto mechanisms available to make that environment more trustworthy , so that I can’t be deceived by my cloud operator sending my data to the us government’

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#99
post #7

Earlier quoted context omitted.

Until this happened MS was still going around trying to convince lawyers to use their Cloud and telling them that there is no issue. Including certain contractual "standard"(1) agreements which would make some of their higher management _personally_ liable for undue data access even under Cloud act from the US!!! (1) As in standard agreements for providers which store lawyer data, including highly sensitive details a…

The max penalty for things like this is actually life inprisonment though. If you, to aid a foreign power without authorization gather certain types of information, it's espionage. There wouldn't be any lawsuit. If you do this kind of things you get arrested, get a trial and then you are in prison forever.

except we are speaking about lying under oath, not espionage, you don't get a trail for espionage because you lie under oath

and leading management also technically doesn't need to know that is happens for it to be doable. Or in other words they have a lot of reason to "accidentally" not know about it/have it overlooked

this means even if it happens they are very unlikely to be charged for anything more then negligence

but the contracts I mentioned above basically state "it doesn't matter why it happens and if you knew or if it was your fault as long as there was the smallest bit of negligence on your side you are on the hook for it personally". So in a situation where they can effectively avoid espionage trials (because they didn't commit espionage, just negligence) they still are hold responsible

if high level management would reliable go to prison for things like that you wouldn't need additional contracts to make sure they actually have insensitive to actively try to find/prevent anything like this/act very non-negligent.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#100
post #60

This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply. "I will never give up customer data" is a very tough promise to keep, if the government threatens you with your business license being revoked, your servers and domains being forcibly seized by the police, and you personally going to jail. (Under the current US administration, we can add "A close examin…

> "I will never give up customer data" is a very tough promise to keep

If you don't have a spine, sure

That's what US companies are seen as from a European perspective: Spineless and untrustable

It's a great sales argument for locally grown software though, so I'm not complaining :)

Post reply on HN