6 ms·
This is a huge deal. I live in Australia and I have been running businesses on the cloud for the last 3 years or so. I have rarely heard the issue of the PATRIO
by jval 13y ago
This is a huge deal. I live in Australia and I have been running businesses on the cloud for the last 3 years or so. I have rarely heard the issue of the PATRIOT Act raised and in spite of there being laws banning the transfer of personal data outside Australia, most people are quite lax about the issue and take the view that the risks are too small to be counted.
Those days are most certainly over. This stuff will affect companies like AWS and Rackspace the most, given that they are competing for contracts with companies who are seriously concerned about who can get at their data. I imagine nobody will flaunt the laws in Australia regarding international data transfers in future, and that countries where no such laws exist will enact some very quickly.
Any cloud based software company in the US which holds large amounts of data that could in any way be deemed to be sensitive is going to have a much harder time pitching to clients overseas who will increasingly opt for a decent local alternative over a foreign one should the option exist. The only thing that American companies can hope for otherwise is that there is no foreign alternative.
The world is not going to come to an end but for a lot of people, their jobs are about to get much harder and the government should be worried about this.
- vertis 13y agoI'm, also in Australia. NB: It's a real struggle to not make this sound paranoid. Just at an individual level, I'm questioning whether it's wise to store my data in a US service that won't afford me the same protection as US citizens. I've already started reducing my reliance on Google, and I barely use facebook, but things like Amazon and Linode are much harder for me to quickly divorce myself from.
- chewxy 13y agoIf you're willing to pay a bit more, there are companies like Ninefold But then again, that is just talk. I still use AWS and Linode religiously. The prices are really hard to beat
- aragot 13y ago> I'm questioning whether it's wise to store my data in a US service It definitely isn't, and I'm wondering why this issue wasn't on top of your mind before that?
- reeses 13y agoUnfortunately, Oz is one of our spying partners, so your ASIO is probably just annoyed that the NSA can't keep its house in order.
- gizzlon 13y agoThe others I can understand, bur Linode? What about something like hetzner? Just checked, and their VPs have more ram and more HDD but only one core: http://www.hetzner.de/en/hosting/produktmatrix_vserver/vserver-produktmatrix http://www.hetzner.de/en/hosting/produktmatrix_vserver/vserv... Aanyway, I though these hosting companies where a dime a dozen?
- BoyWizard 13y ago> in spite of there being laws banning the transfer of personal data outside Australia, most people are quite lax about the issue and take the view that the risks are too small to be counted. I can tell you from working in the finance industry in Australia and APEA, larger companies/banks take this very seriously due to compliance obligations with regulators (APRA, MAS, HKMA, etc).
- hemancuso 13y agoAgreed. I am surprised that Amazon, Rackspace et. al. aren't coming out and letting their customers know where they stand in all of this.
- hackula1 13y agoPleading the fifth apparently...
- lawnchair_larry 13y agoYou shouldn't be surprised about Amazon. They pulled the plug on wikileaks as a favor, and they give the CIA their own private $600M cloud: http://www.datacenterknowledge.com/archives/2013/03/21/amazon-to-build-600-million-private-cloud-for-cia/ http://www.datacenterknowledge.com/archives/2013/03/21/amazo...
- reeses 13y agoAs Facebook, Google, and Yahoo! have demonstrated so far, a company can only make itself look worse by making any statement. Any denial will be rejected as dissembling or sophistry and admissions of complicity would be suicidal.
- jacques_chester 13y agoAustralia isn't exactly a safe haven. There are only a handful of pipes in and out of the country, each of them probably well within the deep packet inspection capability of serious spy gear. I'd be amazed if one of the AFP, ACC, ASIS, ASIO or DSD didn't have their own rooms in selected Telstra and Optus facilities. And not to mention that Conroy wants to do something like what the NSA are supposedly doing; he's just going to outsource it to the ISPs. I've seen an AFP server in a certain government datacentre. Its security was a square of black and yellow tape and the assurance that I would be detained without charge under anti-terrorism legislation if I crossed the tape to take a closer look.
- greendestiny 13y agoBut as an Australian citizen we have our courts and public opinion to try and fight for us. Not to mention the people doing the snooping have far less incentive to pass commercial information along to a competitor.
- jacques_chester 13y agoI'm not sure I follow you. Americans are, theoretically, in a much stronger position vs NSA snooping. US law is meant to make it illegal for their spy agencies to look inwards and the US Constitution has its famous "search and seizure" clause which can, if you find the right judge, have some formidable teeth. As Australian citizens we have no such protections and we have no standing in US courts to get any restitution. We're fair game. Further, as Australians, while we enjoy some protection from our own outward-looking agency (ASIS), the inward-looking agency (ASIO) can and does investigate Australian citizens with a broad range of powers, including powers to intercept telecommunications. Their powers compound of investigation with the Australian Federal Police's powers of arrest, sometimes without cause or notice. In theory, ASIO requires the Attorney-General to grant warrants to exercise most of its powers. Statistics on the warrants haven't been published, so we have no idea if they're granted begrudgingly or rubberstamped. My guess is going to be the latter -- which Minister wants to the one who was "soft on communism/terrorism"?
- 13y ago
- taspeotis 13y agoAustralian here. Government departments are slowly starting to catch on to this sort of thing. One application I work on stores data from DEEWR and FaHCSIA and this year they've "cracked down" on that data going overseas. The application's data (and the bits we get back from the government) has always been stored in Australia on our hardware. My understanding is that some of our competitors using AWS and Rackspace had to work hard to quickly get their stuff hosted locally (or are in the process of bringing it back here). You can get an idea of what DEEWR expects providers using cloud services to adhere to from here: http://foi.deewr.gov.au/documents/policy-use-cloud-hosted-solutions-ccms-software-providers http://foi.deewr.gov.au/documents/policy-use-cloud-hosted-so...
- philwelch 13y agoWasn't Australia already implicated as a collaborator in ECHELON?
- einhverfr 13y agoMy latest startup is Efficito (a Limited Company, registered in the UK). The web site is http://www.efficito.com http://www.efficito.com and our servers are all in Europe. We have built the service up with a very careful eye for security (why we are going hosted cloud first, and multi-tenant is still in the works). You have just given me what I think is a very good possibility regarding a marketing message, namely that we are not subject to NSA orders, and that we take security extraordinarily seriously. We are still looking into whole disk encryption for virtual instances, but key management is a non-trivial problem there to get right. For those who want it I can be pretty sure we'd be happy to work with you to find a way of making the system meet your needs. (Of course given a few customers, we could work with a server in Australia too.) But I also think it goes beyond shipping the data overseas. Suppose you do business with an American company that has servers in Australia (for the record we are registered in the UK, not the US), and they get a FISA warrant? Of course they will send the info over. So you can't only look at where the business's servers are but also where what legal authorities they are obviously subject to.
- Silhouette 13y agoYou have just given me what I think is a very good possibility regarding a marketing message, namely that we are not subject to NSA orders, and that we take security extraordinarily seriously. You certainly won't be the first with that idea. I've now lost count of how many blog posts, tweets, forum posts and so on I've seen in the past week that essentially say, "Is the next big selling point for European service companies that we're not subject to US laws?"
- dmix 13y agoThe UK has quite a strong military sector with their own secret agencies and a strong relationship with America. Could that make them capable of similar monitoring? Does the UK have stronger information privacy laws that the US doesn't?
- einhverfr 13y agoThe laws are build on different principles making them somewhat different. However, one of the things that we pay a lot of attention to is security resilience. The question is, "what has to be compromised before your data is compromised? and is there a way to detect it?" The storage is still something we are working on but you can believe it is a design goal. The EU has very different approaches again to privacy law. I don't know you can compare them. They tend to be more lax with collection and stronger with use. However, we can also help you install the software (open source, reviewed by developers all over the world) on your premises if you would prefer. So our best shot is only for those who really want to cloud host.
- downandout 13y agoThere are technological solutions to address this for US firms. Encryption on the client side, before data is sent to the cloud, would work. I would suspect (hope) that browser makers will quickly introduce features that make sending and receiving end-to-end encrypted communications (email etc.) a thoughtless process - since that is the only way to get people to use it. Even better, perhaps someone will write software that sits on top of the network stack and automatically negotiates secure communications regardless of the origin client software. Maybe some sort of public key registry might come into play.