8 ms·
It's a very common misunderstanding (which is happily spread by US cloud providers) that it matters where the data is stored. What matters is that the data is
by jeppester 4y ago
It's a very common misunderstanding (which is happily spread by US cloud providers) that it matters where the data is stored.
What matters is that the data is stored by - and accessible to - a company which submits to the US laws.
- 8ytecoder 4y agoI don’t think it has been tested in court. It’s akin to a U.S. Court issuing a search warrant on a house in Paris.
- Gwypaas 4y agoWhich is exactly what happened and is causing this mess. https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act No problem at all with GDPR and third countries. They simply need to have a regulatory framework making compliance possible. https://www.imy.se/en/organisations/data-protection/this-applies-accordning-to-gdpr/transfer-of-data-to-a-third-country/ https://www.imy.se/en/organisations/data-protection/this-app...
- GekkePrutser 4y agoThe problem is that frameworks we have with the US keep being shot down by the EU judiciary. First Safe Harbor and now Privacy Shield. For good reason I might add.
- moontear 4y agoYes, it has been tested: https://amp.theguardian.com/technology/2015/sep/09/microsoft-court-case-hotmail-ireland-search-warrant https://amp.theguardian.com/technology/2015/sep/09/microsoft... And that’s exactly what it would be like, though the house in Paris would be owned by a company that has a legal entity in the United States.
- retcon 4y agoEqually it's a sorry indictment of our economic times that the meaning of unlawful has been hammered into a understanding that non prohibition is permission. This aggressive and putative new use is refuted by every founding principle of the common law in Anglo Saxon countries and most of the western world. See the argument of letter vs. spirit for a effect. Ed. cleared up phrasing around new use, replaced meaning with use for .. meaning.
- Georgelemental 4y ago> non prohibition is permission That is exactly how things work. Unless the government goes through the effort of passing a law to prohibit something (and getting approval of the people's elected representatives, and the courts), then the thing is legal. How else do you propose things should work?
- cmroanirgo 4y agoThose "pushing the boundaries" always end up using a similar logic. However, there's always going to be a large segment of society whose rules are based around non financially oriented methodologies, such as: "morals", or directly from spiritual texts which disallow certain practices, or historical "customs". Such things are not "illegal" per se, but it's largely held as being reprehensible by a large number of people nevertheless & causes a large amount of friction within society. Then there's the issue of marketing/propaganda (which the parent mentions as "hammered") whose sole purpose it's to change people's minds in an emotional way. I wish people would learn about Edward Bernays, nephew of Freud, who instituted this. In and of itself, propaganda has never been illegal, but no one likes to admit to being emotionally manipulated. (But when you begin to pay attention to your emotions, you can spot this stuff from a mile away).
- judge2020 4y agoNot sure what the stance being argued is. Should we require companies run morality polls and submit a pre-rollout court to determine the legality of new products that push the limits of human innovation? Also, it's important to note that humans are actually quite bad at this sort of judgement. I'm sure if you showed everyone in Germany in 1980 a computer, and how it can instantly store and retrieve files and documents, and asked them 'is this moral?' they would be against it on the grounds that it would put hundreds of office workers out of a job.
- e98cuenc 4y agoWhy are then things like AWS, Azure, Google Cloud, … legal? Are they? I assume Amazon can access data stored in any of their servers, right?
- darkwater 4y ago> I assume Amazon can access data stored in any of their servers, right? If you encrypt the data with your own key, they should not be able to access it.
- fauigerzigerk 4y agoOnly if you encrypt before upload and decrypt after download, which renders almost all AWS/Azure/GCP services completely useless.
- darkwater 4y agoIn-transit encryption protects you against this attack scenario specifically (if you own the keys obviously).
- fauigerzigerk 4y agoHow so? Amazon, Google and Microsoft need access to your unencrypted data in order to provide most of their services (such as databases, analytics, machine learning). There's not much they can do with encrypted data. They can store it. They can pass it through. That's it. This problem has to be solved on a political level. There is no technical fix and the legal workarounds appear to be exhausted.
- darkwater 4y agoMy RDS data is stored encrypted on disks with a private key AWS operators has no access to [1] (or at least that's what they tell you), and the application layer connection is controlled by a password transmitted over a TLS-only connection, whose private key - again - AWS has no access to. [1] https://aws.amazon.com/blogs/database/securing-data-in-amazon-rds-using-aws-kms-encryption/ https://aws.amazon.com/blogs/database/securing-data-in-amazo...
- verisimi 4y agoIn what sense does it matter? Corporations such as google have legal and financial centers all over the world and these will be structured towards providing the best circumstances for the corporation (tax, legal). On the other hand, don't all these corporations have data centers all over, that replicate data to provide a better service? Which is to say that pretty much most data is available to all legal jurisdictions. At least as I understand it..