7 ms·
Emails aside, this is more about using cloud in services in general. If you use Google Compute or AWS, you are in this boat. This is why U.S. tech can't be trus
by electic 10y ago
Emails aside, this is more about using cloud in services in general. If you use Google Compute or AWS, you are in this boat. This is why U.S. tech can't be trusted.
- pwelch 10y agoAre there any good options for cloud services outside of the US?
- skylark 10y agoCurious: Why would you trust a cloud service operating outside the US more than one operating within? If you use Google, your data is basically guaranteed to be secure - the biggest vulnerability is search warrants from the US government. If you use some provider in another country, the attack vector has to be way larger, right? This is an honest question - people always talk about using their own servers or non-mainstream providers, but I don't see how they necessarily reduce your risk.
- moxious 10y agoGuaranteed to be secure? Are you joking? Aside from the fact that nothing is guaranteed to be anything in the security world, if you go read the documents put out by Snowden there just no way you'd say that. More like it is that there are any number of zero days floating around at all times many of which Google doesn't know, and the government itself is regularly taking data from these companies and then gagging them, and when that doesn't work, rooting them directly. Outside countries are just as susceptible to hacking, but they can't be as easily made into gagged cooperators. And google may have a lot of smart people but they have a collossal attack surface due to sheer size and product offerings. And they're made of humans. They run hackathons soliciting bugs and regularly find them. No one is perfect, definitely not google. The overall security picture out there is grim, and it's very rational for people to control the risks they can and part of that is using outside of the US services
- deleted 10y ago[deleted]
- mtgx 10y ago> If you use some provider in another country, the attack vector has to be way larger, right? If you just mean "Google has more resources than most European services, so it's probably more secure", you have a point, but it's not entirely accurate, and that's because of how Google handles encryption. It prefers to keep the encryption keys to itself, so from that point of view it will always be more vulnerable than services that don't do that - small or large. And if you meant "because the NSA wouldn't target Google, or it would just target those companies more" then I believe that's completely false. Google is absolutely a high priority target for the NSA. Any large company is, no matter where it is. We've learned that by now. Also because Google actually did get completely owned by the NSA a few years ago: https://www.theguardian.com/technology/2013/oct/30/google-reports-nsa-secretly-intercepts-data-links https://www.theguardian.com/technology/2013/oct/30/google-re...
- linkregister 10y agoThe NSA can do way more than just sniffing some network links, please don't call that "completely owned." According to the Snowden leaks, the NSA has done more comprehensive infiltrations, e.g. Belgacom, Petrobras, etc.
- rl3 10y agoSorry, but mass collection on inter-datacenter links operated by one of the largest technology companies on the planet should qualify as "completely owned", at least in spirit. If you insist on using the technical definition, then I'd argue it's very possible that Google could be completely owned after all, in every sense of the term. What Snowden leaked was essentially a glorified TS PowerPoint repository. Crown jewels such as partner company names didn't even make it into that level of access, and for good reason. If the NSA happened to be installing persistent implants on target systems belonging to Google's senior leadership, it'd be so compartmented you'd never hear about it. In other words, we probably wouldn't know if Google was completely owned.
- burrows 10y agoWeigh the cost of corporate controlled robots peeking at your emails against the increased probability of extra-corporate attackers pilfering your data.
- mattmanser 10y agoWhy is the attack vector bigger? Are you saying that everyone else outside the US is somehow incompetent? The 300 million in the US are super special and the other 6.7 billion people are stupid? Cause 'murica? For example all the countries in the EU, Canada, Australia, etc. Or are you saying privacy laws in the rest of the world are somehow worse? For example, the EU has generally much better privacy safeguards and is generally known to be much more consumer friendly than the US.
- dahdum 10y agoGoogle has the resources to secure their systems, the ability to defend against nation state attacks, and billions in revenue at risk for losing that trust. I know of no one that offers the same experience with anything close to the same protection, do you?
- nickpsecurity 10y ago"he ability to defend against nation state attacks" I'm skeptical about that. They got seriously owned by one in the past with their proposed solution switching to Mac's and Linux distros. I don't recall if they acted on that but the fact that they thought it would stop nation-states says something. They certainly have more resources to stop, detect, or recover from black hats than the average user of their service.
- solipsism 10y agoThey got seriously owned by one in the past with their proposed solution switching to Mac's and Linux distros Where are you getting your false news? You can't think Google's response to a nation state attack was to only switch to Macs and Linux. Care to share what you're referring to?
- nickpsecurity 10y agoIt was in multiple sources like NYT and Business Insider that they initially blamed Microsoft with a switch planned. Looking it up again, Wired reports they didn't go that far: just gave employees options with extra information informing them about the pro's and con's of them. https://www.wired.com/2012/05/google-and-windows/ https://www.wired.com/2012/05/google-and-windows/ Of course, this is almost equivalent to original claim given they think switching between operating systems will mean much against nation states with China levels of labor. Especially if it's an Ubuntu derivative. It takes a lot of different elements to deal with them which include strong protections on an endpoint designed with that in mind. Lots of configuration checking and monitoring too.
- nickpsecurity 10y ago"If you use some provider in another country, the attack vector has to be way larger, right?" I think Nexor, Thales, Fox-IT, Sirrix, Data61, and recently ProtonMail might have something to say about such claims. Starting with better security architectures than most vendors in the space. Maybe throw in GPG-based things like Enigmail since Snowden leaks showed NSA worried about it so much.
- jbmorgado 10y agoBecause some countries - namely in Europe - have much stronger personal data protection laws than the US. Switzerland for instance. Also because the country where the data is stored, even if internally has personal data protection laws as lax as the USA, will in basically all cases have much bigger restrains about allowing a foreign government (namely the USA) to access that data. Most people are preoccupied about what their own country's government or a big superpower's government can do with their data, not really what Norway's (another example) government can do with their data if they don't even live there.
- JumpCrisscross 10y ago> Why would you trust a cloud service operating outside the US more than one operating within? Because I'm an American in America. If you aren't in America's sphere of influence, the United States may be one of the best places to host your data. (No data retention laws; freedom of speech; working courts; et cetera.)
- sfifs 10y agoYou would do on-prem and not cloud if your potential legal adversaries included the government because they would then have to come and take your emails from you with a warrant vs. being able to silently take it from cloud providers and compelling them to not inform you. For any reasonably sized multinational, governments are potential legal adverseries.. and so they avoid keeping mail servers and financial transaction data in the cloud
- uiri 10y agothey would then have to come and take your emails from you with a warrant vs. being able to silently take it from cloud providers and compelling them to not inform you. What if they just insert a box upstream of your connection via your ISP?
- fictioncircle 10y agoIt doesn't collect emails routed within the LAN/VPN. You can secure same domain email address communication to prevent such mitm.
- deftnerd 10y agoOVH is one of the largest hosting companies in the world. They have an excellent network, great prices, and a fondness for privacy.
- herbst 10y agoThe company is mostly in france and germany, both part of five eyes. I doubt its really that much better
- herbst 10y agoCheck out Exoscale.ch. DO pricing. Swiss quality. And especially Swiss privacy
- rayiner 10y ago> This is why U.S. tech can't be trusted. Do they not have warrants in other countries?
- mtgx 10y agoIf you are Chinese, it's probably not a good idea to use a Chinese email service (or any of the "joint ventures" between American companies and Chinese ones). It goes the same for Americans. If you want privacy from the U.S. government, don't use American services, or U.S.-hosted services.
- awqrre 10y agoIn the USA, they don't need a warrant for cloud data that is 6 months or older[0], even if it is "private" 0. http://www.bendbulletin.com/nation/2885941-151/no-warrant-needed-for-emails-after-6-months http://www.bendbulletin.com/nation/2885941-151/no-warrant-ne...
- the8472 10y agoThe issue is that the US law enforcement should use a foreign legal system to request legal assistance if they want to do a search in a foreign country, which would allow affected parties to use the local court system to defend themselves. How would you (assuming you're american) feel if the english police entered your corporate office to seize documents and told you if you had issues you would have to deal with it in england? That's how everyone else feels about the US thinking they have jurisdiction over their documents stored on some 3rd party providers which - under local laws - have obligations to maintain the customer's privacy.
- rayiner 10y agoI hadn't thought of that, thanks.
- herbst 10y agoCheck out the swiss Data Protection Act and the Data Protection Ordinance. The difference is HUGE even for swiss govs it is very hard to get swiss data. Outside govs basically have no chance except a few exceptions that are not as easy as shouting out "terrorism" loud once.
- deleted 10y ago[deleted]
- explainthisth 10y agoThis decision is not relevant to something like an AWS instance in the EU.
- pjmlp 10y ago> This is why U.S. tech can't be trusted. Including operating systems, and any other sort of software developed by American companies. So are we prepared to create our own stack for everything? Note you can also not thrust FOSS software developed in American soil without thorough review of what it is actually doing. And those that happen to live there, like in other countries, will need to create their own safe systems as well if they want to be safe from government and any future state police.
- dTal 10y ago>Note you can also not thrust FOSS software developed in American soil without thorough review of what it is actually doing. You can delete "developed on American soil" without affecting the truth of this statement.