Live data from Hacker News

An Apology to my European IT Team

fredlybrand.com

91–97 of 97 posts

Re: An Apology to my European IT Team

#92
post #39

While OP's apology is appreciable, there was more than enough information available in 2008 to understand that his Czech colleagues were right. The Prism scandal may have come as a surprise to US citizens, but the US has been spying foreign nationals and companies for years, and we've long known about it - haven't you heard of Echelon? It was also well known that these systems were used for industrial espionage.

Huh. How is "You should've known!" a useful response to an apology? Of course he should've known, that's why he's apologizing.

It's written as if dubious access to data by US (and other; see ECHELON) security services is a startling new revelation, whereas in fact it has been a known risk for a couple of decades, and certainly a consideration when using hosted services. Here is a European commissioner raising it as a concern with respect to the Data Protection Directive, over a decade ago, for instance: http://europa.eu/rapid/press-release_SPEECH-01-368_en.pdf

Re: An Apology to my European IT Team

#93
post #53
post #39

While OP's apology is appreciable, there was more than enough information available in 2008 to understand that his Czech colleagues were right. The Prism scandal may have come as a surprise to US citizens, but the US has been spying foreign nationals and companies for years, and we've long known about it - haven't you heard of Echelon? It was also well known that these systems were used for industrial espionage.

I "know" that aliens are kept at Area 51. Should I prepare for the invasion? Nothing was "known" until these leaks. It was the conspiracy theory of nut jobs. Now and only now is it "known".

Yes, nutjobs like the EU's executive and legislative bodies, the BBC and the Guardian. Who would ever take them seriously?

Really, ECHELON in particular has been acknowledged to exist by pretty much everybody since 2000 or so.

Re: An Apology to my European IT Team

#94

Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'. American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets. But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally o…

Historically, similar systems have been quite pro-business (or pro-American-business); ECHELON sigint data was used in the 90s to help Boeing win a large contract over Airbus, for instance.

Re: An Apology to my European IT Team

#95

I just wonder why telcos I've been dealing with have always required to encrypt all information which is not classified as public information. All customer, project, system, configuration, documentation, contracts etc. must be encrypted before transit. - Surely they must have known about this. So if telcos won't trust privacy of telecommunication, why should anyone else think that telcos are trustworthy?

(A) Yes, they probably knew about this, at least as a potential risk; while the media has gotten very excited about PRISM, it isn't really that different to ECHELON, which has been effectively public knowledge since the late 90s.

(B) Governments aren't the only ones potentially spying on peoples' unencrypted comms.

Re: An Apology to my European IT Team

#96
post #65

Earlier quoted context omitted.

When your provider is forced by their government to just hand over your data, security is pretty much irrelevant. Anything is more secure than that.

No, not true. There are government and non-government attacks. Even if we assume cloud services are more vulnerable to government snooping, we need to also consider that many more companies and individuals suffer more damage from regular criminal hackers than from the NSA. Avoiding a small risk by increasing your exposure to a large risk is not rational.

Generally this is a good point but I think it's not relevant in this case. The author of discussed article claims that they do business with governments and the knowledge that US government can access their data just by asking their provider to give it to them is not some 'small risk' that you might want to accept to avoid something worse - it's a deal breaker. Expose yourself like that and you have no business.

Re: An Apology to my European IT Team

#97
post #69

It doesn't take much reading of the literature to understand industrial espionage or any of the other substantive risks of outsourcing. Prism or not, when you put your intellectual property on someone else's networks you are taking a risk. Yet most of the managers I see who make this decision just don't care. They ignore the advice of their systems admins and follow the old adage "you can't get fired for buying IBM"…

We'd brought up a wafer fab in the Hsinchu Scientific Park in Taiwan before - so we weren't strangers to the concerns about industrial espionage. Several of us have done a lot of work with the government and we'd manufactured some very sensitive products (as does the current business). My apology is really around the fact that at the time we were trusting that such programs would not exist here (this was before expla…

we were trusting that such programs would not exist here

It's still not clear what programs you are talking about. Because google provides no access logs "someone could go into our account and take confidential information, and we would never know". What does that have to do with Echelon or Prism?

Post reply on HN