7 ms·
(author here - if there are any questions, please let me know!)
by ahubert 5y ago
(author here - if there are any questions, please let me know!)
- jollybean 5y agoWhy is the EU trying to regulate outside it's jurisdiction? Why doesn't the EU simply provide a 'core' set of servers, which they operate to a high degree of fidelity and robustness so that 'should something go wrong' ... then the EU still has these resilient services to reply upon? I don't see how someone doing a public service should arbitrarily come under such scrutiny.
- guerrilla 5y ago> Why is the EU trying to regulate outside it's jurisdiction? My first question is are they or is this the authors view?
- latk 5y agoIt is primarily the authors view. The proposed regulation – like many EU regulations – can also apply to non-EU entities. In this sense, the EU does try to exert extraterritorial jurisdiction. However, this is constrained to the case where the non-EU entity targets people in the EU, so somehow participates in the EU market. The origins of this “targeting criterion” actually come from consumer protection cases, where it's easy to understand: if you advertise your goods or services to people in a particular country, you'll have to play by that country's rules.
- jollybean 5y agoNone of these systems advertise their goods or services anywhere really. So that's going to be a funny day in the ECJ.
- dncornholio 5y agoI can make the analogy that public transport is a public service, but that doesn't mean people have to drive in old and unsafe busses and trains right?
- BuyMyBitcoins 5y agoIt’s the nature of governments and bureaucracies to try and control as much as they can. The kinds of people who draft these regulations aren’t interested in limited legislation. The United States is particularly guilty of this - we frequently demand that other countries follow our regulatory rules, especially around banking and “anti-terrorism”.
- kazen44 5y ago> It’s the nature of governments and bureaucracies to try and control as much as they can. The kinds of people who draft these regulations aren’t interested in limited legislation there is not really any other way to play the geopolitical game sadly. Every goverment on earth is doing this to keep themselves stable, some are just far more succesfull then others.
- emouryto 5y agoWhy not? Let's see... the past year the was a big scandal because apparently multiple non-profits were selling the .ORG top level domain name for $1B. They got these top level domain for free from the US government (or some institution thereof). I would certainly like the EU to regulate more of the Internet instead of it being an US territory.
- martimarkov 5y agoThis is ICANN’s responsibility and not root DNS servers. They are completely separate entities. If you dislike this go shout at ICANN. It’s was US organisation - now it’s a “private” one[1] [1] https://www.icann.org/en/announcements/details/stewardship-of-iana-functions-transitions-to-global-internet-community-as-contract-with-us-government-ends-1-10-2016-en https://www.icann.org/en/announcements/details/stewardship-o...
- herbst 5y agoIt is still a US company regulated by US laws isnt it?
- krona 5y ago> I don't see how someone doing a public service should arbitrarily come under such scrutiny. It doesn't seem arbitrary to me. The service provided exists in many EU countries, and therefore must eventually be harmonised. This is the prime directive of the project.
- jollybean 5y ago"and therefore must eventually be harmonised. This is the prime directive of the project" That's not a very good prime directive. Don't regulate things that don't need to be regulated, i.e. unless there is a very material benefit from it. If the EU is concerned about WW3 level resiliency for these services, they can accomplish that themselves with a few cord, 'hardened' services that meet their criteria. For 'regular operations' it seems we're going quite well right now. Unless there is a threat posed by these heretofore independent operators ... then I'm don't see any obvious material benefit here. I'm wondering if somehow these entities could be compromised in a way that makes them a problem, more so than just 'going offline', in which case, maybe there are some benefits.
- oaiey 5y agoNot they cannot. A DNS request in China is not targeting a European root but a local one. And that can affect a European citizen.
- martimarkov 5y agoUmm idk if I put 1.1.1.1 as my DNS which root is it targeting? The one in China? Or if I put 0.0.0.0 (IP of EU run DNS server backed by EU run root) then is it still China? There is a simpler solution rather than enforcing EU oversight over root DNSes.
- tick_tock_tick 5y agoCloudflare is one of the private operators of root servers mentioned in the article so you would be using the F root server. https://blog.cloudflare.com/f-root/ https://blog.cloudflare.com/f-root/
- mattashii 5y agoIt doesn't, really; see paragraph (65) in the document [0]. It states something along the lines of "if you're providing services stationed in the EU, or services directed people that live in the EU, then you must comply with these regulations". Basically, an import regulation for operators that do not have a presence in the EU (but do target the EU market), and an operating regulation for those that have a presence in the EU. [0] https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=72172 https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=72172
- jollybean 5y ago'target the EU market' is vague. These are independent operators, NGOs etc, services being 'used by EU citizens' not really 'targeting Europeans'. From a liability perspective, to the author's point these services I suppose would have to just filter out European sources? Why would they publish a regulation so obviously vague, full well knowing the reality on the ground? Why wouldn't they use language that unambiguously places NASA etc. firmly 'in our out' of the regulations or, some criteria which they would be one way or another? Seems odd.
- oaiey 5y agoThat is exactly how gdpr is set up. Which is good. Regards NGOs: just because you do not make money does not make you a saint. Regards vagueness: if you want to survive in an agile environment without rewriting every second day, vagueness is the way to go.
- EricE 5y ago>That is exactly how gdpr is set up. Which is good. So if the US comes out with "GDPR- The Next Generation" with similar mandates towards the EU would that also be "good"? Asking for a friend.
- oaiey 5y agoFISA courts and the law they are based on? The US is explicitly or implicitly doing this all the time. Or the Hague invasion act which is pretty much that case (US soldier are protected abroad against international treaties).
- oneplane 5y agoIf you want to look at it from that perspective: the same reason the US does it. People also tend to forget that providing a service (in whatever fashion) doesn't exist in a vacuum, there are the services and then there are the consumers of those services and they might have certain freedoms and rights that the locality of the service in question might not honour. Take the right to control your data for example, the US isn't very good at providing that with the services they offer, and they'd rather not have that freedom and rather make those few percent more money.
- kazen44 5y agoAlso, it makes sense in the broader EU strategy of becoming less reliant on the US. The EU has a good amount of soft power, this is just testing testing it's waters in directing policy more directly. (other examples are the Iran deal after the US left, and Intervention in Africa) Geopolitically, this makes a lot of sense, and i think the idea has good intentions, but the implementation of the law is where it falls short.
- guerrilla 5y ago> The current version of the NIS 2 directive explicitly says the EU will regulate the root servers, and therefore NASA and the US Department of Defense in this way Is the latter part of this your conclusion and interpretation? I haven't looked at the source material but are you sure they aren't just referring to root servers operating in the EU or by EU companies. I find it hard to believe they would consider DoD servers within their jusrisdiction.
- tester756 5y agoI have question about your other post which I found interesting >https://berthub.eu/articles/posts/how-tech-loses-out/ https://berthub.eu/articles/posts/how-tech-loses-out/ You wrote >We barely develop any software here anymore. So even very European companies like like Nokia and Ericsson, that are now trying to tell us that they are building our European telecommunication infrastructure. They’re actually not, they’re getting that built by other people in other countries far away. Anything having to do with server and PC development and manufacturing, there’s nothing left of that in Europe anymore. As far as I've been told, then there are R&Ds in e.g Cracow, Poland or Wroclaw (probably nor R&D) that actively recruit or even train people What are they doing then?
- guerrilla 5y agoYeah, Ericsson employs about 13,000 people in Sweden and I personally know they develop a lot of telco software.
- squarefoot 5y agoMy latest news (~2 yrs ago though) from friends working at Ericsson is that beside hardware they also started outsourcing software to far east entities. I don't have details, but over here they sack about 300 people every year, mostly developers. It might be different in Sweden though.
- BenjiWiebe 5y agoHow many do they hire per year? 400?
- Jolter 5y agoEricsson has hired several thousand engineers per year in the past couple of years, globally. You can see the history of their Wikipedia page for the nitty-gritty...
- squarefoot 5y ago
- oaiey 5y agoWhat is your expectation what a state actor like the EU should do to protect it's citizens infrastructure? Rely on a third party like the US which has secret courts and gives a shit about EU citizen privacy, their property or their lifes? Or give it in the hands of the industry? Which only has one motive: making money. Or leave it unregulated with no safety for no one? DNS is about trust. We need trust into this thing. And honestly: i would not trust DNS offered in China and most likely also not the US, or 99% of the carriers
- sam_lowry_ 5y agoSecond that. The article lacks the good parts. It's clear that the rapporteur has not figured it out yet how to deal with the root DNS servers, but there is a broad consensus over the strategic autonomy goal [1]. One way or another, EU will force its way. Should it do it by e.g. empowering DIGIT to run root DNS servers? They will for sure tender it off to a murky consortium, but at least there will be a positive political move. [1] https://en.wikipedia.org/wiki/Strategic_autonomy https://en.wikipedia.org/wiki/Strategic_autonomy
- oaiey 5y agoI also think that the article is focused too much about the auditing and regulations instead of suggesting a better model.
- EricE 5y agoI love the assumption that there is "a better model." This reeks of the quintessential "let's solve a problem that doesn't exist." Here's an even better and more logical idea - for those who have concerns about the current DNS root server arrangements, what specifically are they? And what would you propose as solutions to their perceived deficiencies? Bonus points if you can raise actual technical arguments and not just feelings.
- oaiey 5y agoFair point. I don't have a different idea in the current geopolitical situation.
- pmontra 5y agoFirst of all, I praise the initiative and the explanation. But not everybody tweets. Is there an email address to send that message to?