5 ms·
Onli is talking about the potential for US authorities to order US companies to disclose information hosted by them regardless of the location of their services
by grabeh 10y ago
Onli is talking about the potential for US authorities to order US companies to disclose information hosted by them regardless of the location of their services, not the actual security of the data. The issue of US companies being compelled to disclose is the subject of ongoing litigation between Microsoft and the US. I believe the Supreme Court will hear arguments this year.
Of course if you are encrypting hosted data and AWS has no access to the keys, then that gives comfort over the disclosure. The relevant authorities/local authorities would have to come to you for disclosure of the keys and you would have any protections applicable under local laws...
- Beltiras 10y agoThat would exclude AWS from an awfully large segment of data hungry industries. Operating in the EU AWS has to comply with GDPR for at least the operations they have located in the EU. Frankfurt is safe.
- onli 10y agoIt is not. See https://www.extremetech.com/extreme/186302-us-government-asserts-unilateral-right-to-access-private-data-even-if-its-stored-outside-the-us https://www.extremetech.com/extreme/186302-us-government-ass... for a popular explanation why. AWS being excluded from business is exactly what those companies are arguing.
- Beltiras 10y agoStill being litigated [1]. Last ruling was for Microsoft's position. [1] https://en.wikipedia.org/wiki/Microsoft_Corporation_v._United_States_of_America
- onli 10y agoThat's a good caveat. Still: Being litigated means the US is trying to achieve a state which is explicitly unsafe. Which for me means already that AWS-Frankfurt is not safe. Especially for something like medical data. The potential danger is way too big, especially since we know that the US-agencies will siphon the data anyway, regardless of what the court rules. Think business: Do you really want to face the media backlash when your competitor lances the story that the medical data you collect goes directly into the tiny little hands of Trump, and to the NSA?
- Beltiras 10y agoIf they are using extra-judicial means to get at the data I have no recourse anyways. I will have to store it somewhere and a dedicated attacker will always (eventually) find a vulnerability. The standards I have to implement do not state that I must keep the data out of the hands of attackers. They state principles and methods that make it less likely. When the regulators come knocking after an 'incident' their levying of fines will depend on standards and regulation compliance, not the leaked documents. You have an unreasonable expectation of what can be done.
- onli 10y agoNot hosting private medical data on a server controlled by a country with no regard for privacy of those patients is not an unreasonable expectation. It is a basic requirement for this kind of business. There will come a crackdown on that kind of malpractice. I hope you reconsidered till then.
- grabeh 10y agoWhat would exclude AWS from large segments? Having to hand over data? Actually various governments around the world have the ability to compel entities to hand over data if in support of an investigation. It is not a concept unique to US entities. This is a reality we deal with and AWS will always fight hard to resist that disclosure. As I say, if you encrypt the data then AWS can only ever hand over that encrypted data. That is the comfort that you can offer users. Since you mention the GDPR, that regulation as with previous legislation contains carve-outs permitting disclosure of personal data to comply with legal obligations, for example assisting in criminal investigations. Also, the GDPR, whilst introducing certain obligations on processors, mainly deals with controllers, which AWS is not.
- Beltiras 10y agoIf I have a subpoena issued against me for data it doesn't matter where the data resides. Having it stored in the EU insures we use EU courts to litigate the issue.
- grabeh 10y agoAs you are in Germany then I would say you're out of scope for subpoenas direct from US governmental authorities. They would however look for assistance from German authorities who may or may not be minded to comply. Of course different jurisdictions will react differently to a request from a US governmental authority for assistance (Russia for example would be unlikely to comply I imagine). As you say therefore, in terms of direct action against you, you would be able to fight in your courts. In terms of the host of your data, the location of the data is of relevance, as is the jurisdiction in which the host is based. It's related to the Microsoft v US litigation. The main purpose of the litigation is to decide whether US entities hosting data outside the US have to comply with warrants to disclose that information (and in the process bypassing local protections/giving you the opportunity to fight in local courts). If Microsoft is successful in the litigation, they won't have to comply with US issued warrants in relation to data stored outside the US. If Microsoft loses, then you would be better placed using a hosting provider with no links to the US if you want to reduce the chances of data being disclosed to US governmental authorities.