5 ms·
This seems reasonable, they have a warrant and the judge seems to have considered the case fully. I don't get why so many people are advocating a world where t
by JBReefer 10y ago
This seems reasonable, they have a warrant and the judge seems to have considered the case fully.
I don't get why so many people are advocating a world where the government can't do this. Why should your email hosting provider have the ability to make law enforcement decisions? Why should email be treated differently from something like my bank account or diary? This seems like the optimal outcome.
- deleted 10y ago[deleted]
- Spooky23 10y agoThere's a lot of libertarian fantasyland stuff in tech forums. In reality, there's a built in tension between what a prosecutor or regulator wants and the interest of the individual. 200 years of law in the US was built around your "papers", mostly held in your home or on your person. Now you have this new world where your "papers" may be a detailed diary of every place you've been for most of your life. My wife's phone has immediate access to 60,000 pictures with date and geo-stamps dating back to 2003. Oh, and by the way the storage of this stuff may be on a phone or computer in your possession, or in the hands of a 3rd party like iCloud, Google, etc. The law is behind in it's understanding, and the various authorities want to have the ability to have total information awareness.
- deleted 10y ago[deleted]
- JoshTriplett 10y agoIt's a question of jurisdiction. A company with subsidiaries in multiple countries necessarily needs to ensure that the subsidiary in a country complies with all the laws of that country. However, that doesn't mean that, for instance, it should be possible to serve a warrant in one country to obtain data controlled by a subsidiary in another. It's entirely possible to compartmentalize hosting and authorized access, such that one subsidiary has no access to the data stored by another. That's critical if, for instance, you need to meet regulatory requirements such as the "data protection" laws in the EU. Rulings like this one, if not successfully appealed, will make it nearly impossible for any company with subsidiaries in multiple countries to meet such regulatory requirements.
- avar 10y agoLet's say a Russian company opens up a chain of coffee shops in the US, has surveillance cameras for theft prevention, keeps various records on its customers etc. Now the Russian government issues a warrant to demand data from the US subsidiary. Do you think that US jurisdiction should have no say in the matter? If the Russians compelled their US subsidiary to hand over the data in violation of US law, how long do you think they'd be allowed to operate in the US? The end result of this US overreach will be trade wars and the further rise of national enclaves of the Internet. I'd argue that that's not in anyone's long term interests, least alone the US's.
- ocdtrekkie 10y agoOn the contrary, I'd argue that it's in most users' interests for there to be national enclaves of the Internet, for just this reason: Your data is within the jurisdiction of the laws of your country. If this is clearly defined, you do not have to worry about another country's laws, like Russia, affecting your data. It isn't in certain corporations' interests though, because the whole cloud provider thing hinges on shoving everyone's data into a small number of datacenters globally. I think this is an example of the quite common situation where corporate interests and individual interests are not aligned.
- oconnor663 10y agoFor what it's worth, there are technical limitations to this idea. IP routing makes basically no guarantees about what countries your data will travel through on the way to where it's going. Crypto helps with this, but it can't solve everything. (Sometimes all you want to know is that I visited a certain website, for example, and it doesn't matter that you can't read my traffic.)
- cryptarch 10y agoThere are limitations caused by the software configuration of most AS's. Significant work is being done on novel approaches to IP routing with better security, scalability and control guarantees by ETH Zurich, as part of the SCION project. It's sponsored by the EU, Google, Swisscom, the NSF and a few other entities. Link: http://www.scion-architecture.net/ http://www.scion-architecture.net/ This is already "live" in the sense that it is implemented and there are 14 router nodes active, and it is meant to be incrementally deployed. I haven't gotten around to hooking up a client myself, that will be an interesting weekend project someday. Any interested ISP can set up their own node and join this project. Some cool things about SCION and its extensions: * Isolation domains: can be used to enforce traffic to never leave a given routing sub-plane, for instance a country or a state * SIBRA: volumetric DDoS mitigation and enablement of the creation of "dynamic interdomain leased lines" * HORNET: high-speed onion routing
- tomjen3 10y agoLack of trust. You need secret warrents, national security letters, etc? I assume that with all the we can't tell you this and we can't tell you that, you are up to some nefarious thing. Now if you have shown consistently that you had opportunities to cheat me but haven't, I might trust you on this one. The US government? Fuck no.
- btilly 10y agoIt is because solving a non-problem here creates very real ones. And your analogy is backwards. The reason why it is a non-problem is that there is an established procedure for this that works quite well. Take the warrant from a US court to a court in the other country, cite the appropriate international treaty we have with them, and then access the information in that other country in accord with local law. This is how we have to go about getting access to foreign bank accounts. Or getting your personal papers searched if you lie abroad. The same standard should apply to emails. But US courts wish to apply US law to emails and people who do not live in the USA. Why should US law apply to them? What are the limits of a government of one place applying its laws elsewhere? Do you wish France to be able to access your emails? How about Iran? Furthermore complying with US decisions like this puts Google in conflict with foreign laws about data privacy. This issue is already costing them a lot of lost business. What penalties are appropriate for their violations of local law?
- comex 10y agoThere are a few problems with your proposed solution, based on the facts as described in the opinion (and thus as alleged by Google's lawyers): First, Google's architecture supposedly constantly moves data from place to place, so US law enforcement could spend considerable effort going to a court in France and convincing them they should hand over the data, only to hear, oops, while you were doing that we moved it to Canada. It also potentially splits data into many parts, requiring the US to go to several different courts. (Google also didn't even say which country or countries the data is stored in, though I suppose the US could probably subpoena that information.) Second, Google says that the only system they have for giving data to law enforcement requires going through employees in the US, regardless of where the servers to be accessed are located. Makes sense, since their architecture is location-agnostic by default, and handling law enforcement requests is a specialized job. But a decision from a foreign court is not binding on those employees! US law enforcement would have to try to get the country hosting the data to go and physically seize Google's servers, and manually search through their hard drives. Admittedly, they'd probably only have to pull a stunt like that once before Google decided to get more cooperative, but it's still a messy situation. FWIW, I agree with your concerns about foreign data privacy laws, but the solution can't be to effectively make certain data immune to court-ordered access of any kind. (Well, at any rate, such a solution would be contrary to political orthodoxy even in the EU, though cypherpunk types might be happy with it - a category I count myself in to some extent. :) Maybe the US needs to pass laws explicitly addressing this situation, but considering the current political situation, I wouldn't expect that to happen anytime soon…
- djsumdog 10y ago> "...an individual who resided in the United States and was a target of an investigation pertaining to the theft of trade secrets from a corporation located in the United States..." Google turns over data like this all the time. In fact, ever thing seems reasonable about the warrant, so why are they fighting this? It's right there. I suspect somewhere within either the Google corporate structure or structures of one of their trusted partners are individuals that have done some thing that could potentially put Google in hot water. It's just a theory, but I think it's plausible.
- stuckagain 10y agoThe linked decision, if you read it, discusses this. Google has in the past responded to similar requests but after the Microsoft decision they responded differently.
- deleted 10y ago[deleted]
- raesene9 10y agoThe problem seems, to me, to be one of jurisdiction and international legal privacy differences. US corps like Google want to be able to provide services to people all around the world. If they can be compelled by a judge in any country to provide data on any user, that could cause a lot of problems. for example say a user in Germany makes a deal with a user in the USA which then goes bad and the case is heard in the US. In Germany the privacy laws are different and could prevent the data from being used in the case. Can a US judge require that data to be produced? Next step in the chain, a russian user and a US user have a deal, which goes bad, and a russian court requires the data from the US user to be provided. Should it? Now the obvious argument here is one of american exceptionalism, that google is a US company and therefore needs only concern itself with US law. Unfortunately that leads down the line of companies in other countries not making use of Google's services as they can't legally allow data they process to be subject to US laws...
- tn13 10y agoSo you are fine if Chinese government wants your data stored in USA by a Chinese company ? The whole point of keeping data in a different country is to keep it inside the jurisdiction of that country. This makes American companies less competitive. US government already treats non-Americans like shit, they might want to access all emails of all non-American people using Gmail where the data is stored in EU or India. I think American companies must lobby with foreign governments to put an end to this.
- neom 10y agoThis is all very normal indeed and is well covered under MLAT. Have process MLAT requests before, pretty standard stuff. I'm pretty sure this is the relevant treaty: https://www.state.gov/documents/organization/180815.pdf https://www.state.gov/documents/organization/180815.pdf
- Gonzih 10y agoUS government should not be able to make decision like that when it comes to data of foreing citizens on foreing soil.