Slashdot Mirror


Ask Havenco's CTO Anything You'd Like

A few days ago you read here on Slashdot about the datahaven called Havenco poised to open six miles off the English coast, in the semi-recognized, undeniably eccentric principality of Sealand. Havenco CTO Ryan Lackey has graciously agreed to answer questions from Slashdot, and to involve others on the Havenco team in answering questions he can't. C'mon -- how can you not be curious about an off-shore datahaven in an anti-aircraft bunker? Ask questions in the space below, and we'll forward 10-15 of the highest moderated ones on to Ryan. [Updated 15:40GMT by timothy:] Remember, many of the obvious questions are answered on the Web sites above or in the comments of the first story. Fire away with meaty technical questions -- they're up for it!

38 of 226 comments (clear)

  1. Re:Connectivity by um...+Lucas · · Score: 4

    Forget about internet connectivity. In all honesty, I'd like to know what sort of defense systems you're country has? What are you going to do if some country gets angry about what you're posting and decides to invade? Honestly! I mean, anyone can take of say, martha's vineyard, with just a few people and declare it it's own independant country, but the US could and would drive them out in a heartbeat. Likewise, I could find a desserted island in the pacific and say it's mine, but only until a country with more weapons than me decides they'ed like it instead... You could ally with another country, and use their arms as your own, but in all likelyhood, the entire purpose of this country seems to be to be able to disregard other countries laws... Thererfore, places like the US, France, etc... aren't very likely to step up to defend you...

  2. DoS by dingbat_hp · · Score: 5

    Sealand will inevitably have thin comms links and so will be more exposed than most to a DoS attack. Recent cases have involved ISPs pulling user sites simply for being attacked in this way - they accept the target site is blameless, but pulled it "for the good of the majority of users" and the restoration of their own comms.

    How would Havenco respond to such an attack ? Taking the moral highground, or the pragmatic approach of letting individual users be picked off ?

  3. Any plans on expanding your island? by georgeha · · Score: 3

    From the pictures and schematics I've seen, it looks small, especially if you intend to cram it full of servers, dishes, generators, fuel, supplies and security guards.

    Are you going to sink more barges/piles to expand your area?

    George

  4. Why and what? by Julian+Morrison · · Score: 5

    What motivates you to set up a data haven? Are you motivated primarily by libertarian principle, or do you intend it mostly as a way to make money from sealand's sovereign status? Or both?

    Will you allow data that does any of the following:

    - evades taxes or excise?

    - breaks local morality and legislated morality (including where oppressive eg: Iran)?

    - belongs to political dissidents?

    - belongs to terrorists, organised-crime, etc?

    - is uploaded and maintained completely anonymously?

    - is maintained with absolutely no access granted to anyone trying to prosecute on grounds of its content?

    Do you percieve what you're doing as moral? If so why?

  5. 3 questions by milgram · · Score: 4

    My first question is slightly silly, but did this idea arrive as a result of Cryptonomicon? The second is, where did you look for funding, and how will your backers affect your business plan? Third, are you planning on having banking services?

    1. Re:3 questions by zorgon · · Score: 4
      Don't be silly. Not Cryptonomicon, but Count Zero!

      {Conroy and Turner approach a seemingly abandoned oil platform by helicopter: the helipad is marked by a large biohazard symbol...}

      Conroy: Somebody tried to set it up once as a data haven, back before the war.
      ...
      Turner: There a biohazard down there?
      Conroy: Not anything you're not used to.

      from Count Zero, by William Gibson, 1986!

      Not to say that Stephenson's a Johnny-Mnemonic-Come-Lately, but hey, let's get the attributions correct ;)

      --

      I am quite civilized, and I should be brought a beer immediately. -- Bruce Sterling

  6. Re:Physical assault & freenet by xyzzy · · Score: 3

    And are you, as employees/founders of a company, prepared to be carted off at gunpoint, and possibly put on trial, for the activities of your business?

  7. justification by matticus · · Score: 3

    you're providing a service to people who in some cases can't get it anywhere else. how do you justify the fact that people are going to hold illegal data in your facility in the name of free speech?

    1. Re:justification by Psiren · · Score: 4

      Ah, but illegal to whom? Thats the whole problem, whats illegal in one place isn't necessarily so in another.

      Now weary traveller, rest your head. For just like me, you're utterly dead.

  8. Connectivity by beff · · Score: 5

    I agree that the best method is to retain good relations with your neighboring countries, but if relations go sour, what technologies are you implementing to ensure that no other country can sever your connectivity to the rest of the world?

  9. Real sovereignty? by mpk · · Score: 5

    The Sealand folks seem to base their view of sovereignty on a decision in a relatively lowly UK court taken a while ago. While at the moment they may be nominally independent, it seems to me pretty likely that if the matter was taken either to a higher court or to the international community in general, it would really be found to be part of the UK and not a sovereign state at all -- and as it's an artificial structure, the Royal Navy could presumably claim ownership, as they put it there in the first place.
    Given this, and the fact that from what I've read, Havenco only has one connection to the outside world running directly to the UK, whereas a really useful data haven would, to my mind, need several connections to several different countries to be really viable or immune from legislative interference -- is this really intended to be a viable idea, or just a publicity stunt?

  10. Do you have a white long haired cat? by Anonymous Coward · · Score: 4

    And how are those plans for world domination going?

    Are you going to have Jill St. John stop by for a photo op? Or maybe Plenty O'Toole?

  11. Re:platforms and access by inflexion · · Score: 4

    This is all covered on their website.

  12. Read The Website before asking questions. by Pilchie · · Score: 3
    Directly From their site.

    Hardware - VA Linux Boxes.
    OS - Debian, RedHat, OpenBSD, or FreeBSD 4.0
    Access - Doesn't say, but I am assuming ssh, ssl, etc, since it says open secure protocols.

    Why don't people read the available info, before wasting questions asking stuff that is easy to find out, and doesn't require their CTO?

    Oh well people are just lazy I guess.


    >~~~~~~~~~~~~~~~~
    --
    >~~~~~~~~~~~~~~~~
    Pilchie
  13. Cryptonomicon? by (void*) · · Score: 4

    My question is this: were you inspired by Cryptonomicon, or did Cryptonomicon scoop you? If the former, then this is not the first time SF inspired real world events, a self-fulfiling prophecy. If the latter, then this must be one of the quickest SF predicted prophecies. How does it feel to be in this position? I gather you are already sold on the necessity and market for a data haven. How seriously do you take Stephenson's warnings of governmental or corporate harassment?

  14. Do you need any help? by BoLean · · Score: 5

    Is there any way that we internet users or the Open Source Community could help with Heavenco? Are there any specific software/software security need that you have? Have you considered working with individulas/groups from other countries to help politically support your operations from their native soil?

  15. Is HavenCo in Sealand just a demo? by Chris+Worth · · Score: 3

    You've chosen to try and execute a great idea. Like all great ideas, it needs demo'ing to possible investors and customers before it can really fly.

    My question: is HavenCo in Sealand simply a flashy demo for a planned 'public beta' somewhere in Asia or the Carribean later on?

    Thank you.
    Chris Worth

    --
    - Read fiction at www.espressostories.com
  16. user-side threats by laborit · · Score: 5

    Let's say that you do manage to completely secure your clients' hardware and data. Do you think you can also completely obscure the fact that said client is doing business with HavenCo?

    If so, may we have more details on how?

    If not, do you think that certain governments will make it a crime to simply do business with Sealand? I understand your explanation that you're not undermining the authority of other governments -- but you are undermining their power to legislate away certain activities to which they object, and I imagine they won't like that. In a world which places little value on a citizen's soveriegnty against hir government, there would be few reprucussions to (say) the U.S. making it illegal to purchase your services, but it would put a big dent in your ability to do business.

    - Michael Cohn

    --

    -----
    Go ahead, blame me... I voted for Nader!
  17. How can you avoid ISPs Terms and Conditions by matthew.thompson · · Score: 3
    I'm interested to know how HavenCo - which will invariably have to connect into a French or, more likely, British ISP - will host material that may be considered illegal in the nation to which the data is travelling to.

    Most terms and conditions for ISPs restrict you from undertaking illegal activities and are recognised as being legal in the country that service is obtained from. If you HavenCo host something that is disallowed in the Terms and Conditions you agreed to then claiming International independance is not an option.

    About the only way I can see of getting round this is to take bandwidth from a much more liberal country who are more likely to accept the money without questions.

    --
    Matt Thompson - Actuality - Insert product here.
  18. possible questions for HavenCo by leto · · Score: 5

    1...The website displays a copyright logo. Did
    Sealand sign the Berne Convention, and thus does
    it respect copyright?

    2...Explain who is the real owner, because outsiders are confused with havenco, principality-sealand.net and sealandgov.com

    3...Will I be allowed to store encrypted files there that HavenCo can't possible read, condone nor condemn?

    4...Why does Havenco insist on policies that allow them to remove content based on their disgretion? How many judges does Sealand have to deal with this, or will Joe random Sysadmin play judge?

    5...How will havenco prevent their backbone ISP or that ISP's country from interfering with Sealand/Havenco?

  19. HavenCo's justification by The+Dodger · · Score: 5

    What exactly is HavenCo offering? On the one hand, you refer to yourselves as "the world's most secure managed colocation facility" (setting aside for the moment the fact that HavenCo is not a co-location facility) and on the other, your website makes vague references to the fact that Sealand is a sovereign territory.

    Five years ago, when I first heard of Sealand and it's alleged sovereignty, I looked into it as a potential site for a hosting facility. However, I concluded that Sealand's claim to sovereignty wasn't anywhere near strong enough to ensure that it could avoid being subjected to British law (in particular financial law). Given the fact that it exists, in my opinion, because it's owners are viewed as relatively harmless eccentrics by the British authorities, and that it is not recognised as a bona fide principality by any other nation (notwithstanding the visit by a German diplomat), I concluded that if a hosting facility were to be established on Sealand from which, subsequently, actions were carried out or services provided, which sufficiently antagonised a bona fide government, steps would be taken to ensure that such actions or services ceased.

    In short, whilst the idea of Sealand existing as the world's smallest independent nation is a good read in the newspapers, and makes for terrific brochure blurb for a company like HavenCo, I don't believe it to be a truly tenable position.

    Security was something else I looked at. I looked at four methods of connectivity - fibre, microwave, sattelite and packet radio. Any means of connectivity (except, perhaps, for packet radio), exposes a "Seahouse" to the prospect of it's connectivity being shut off at the mainland (whether it be in the UK or the Continent). From a pure security point of view, fibre is obviously the best option. Microwave, sattelite and radio can be snooped both from Earth and space. Sattelite and radio links have their own problems with regard to latency.

    The provision of traditional utilities to a "Seahouse" present further problems - unless a cable could be installed to bring power from the mainland (which, again, leaves the facility open to being shut down by mainland authorities), such a facility must generate it's own power. I dismissed wind and wave as too unreliable, leaving diesel-based generation. This would be expensive and the possiblity of being unable to resupply because of bad weather arises (note that, at one point, Sealand was abandoned because of bad weather). Any interruption to power would result in disruption of environment control (AC, fire suppression systems).

    The actual environment itself was also a concern - I'm not sure how suitable a sea-tower is, as a facility for hosting sensitive computer equipment.

    Finally the security of Sealand itelf was a concern. I conducted an analysis aimed at examining what sort of operation would be required to attack, conquer or destroy Sealand. With the help of an individual with experience of this type of military operation, I determined that carrying out a professional operation designed to invade and seize terporary control of the tower, would cost somewhere in the region of £200,000 (around $320,000). This would involve sourcing weapons and experienced personnel, as well as arranging for a suitable method of accessing the target.

    Conquering the tower would be a different matter, requiring a long-term commitment to both the security and logistics of the tower. Destroying it by UDT methods would not be easy or cheap, although severaly disrupting it's habitability by something like mortar attack would be a lot cheaper.

    In the end, I decided that Sealand sovereignty/legal position, security and suitability as a hosting location were not up to scratch.

    I find it interesting that HavenCo have found otherwise. I note with interest that the HavenCo website indicates that they intend to open hosting facilities in other countries, and I find myself wondering whether the SeaLand thing is merely a publicity stunt/gimmick, purely for the purpose of impressing the press, potential clients and investors.

    Finally, addressing that issue of the definition of co-location. A co-location facility allows companies (typically telcos, ISPs) to locate equipment within the same building, to enable interconnect/exchange of IP traffic. HavenCo says that it will not allow clients to place it's own equipment in the facility. If this is the case, then HavenCo's Sealand facility will be a hosting facility, where clients are constrained to choosing equipment which HavenCo can supply/support.


    The Dodger
    dodger@2600.com

  20. What about Terrorist Threat? by tringstad · · Score: 4

    Everyone seems to be concerned with other governments capturing Sealand or claiming ownership of Sealand. I think it more likely that they would just sever connections to prove their points, and that has already been addressed.

    But what about terrorists? What if some terrorist organization sees Sealand as a get rich quick scheme, and wants to capture and hold hostage the sensitive data of some of the worlds largest companies? Threats to divulge internal secrets, data loss, exposure of personal information of clients and accounting records have all got to sound like a good opportunity to someone out there.

    Surely, government militaries cannot be expected to defend what is clearly a corporate undertaking (though I suspect some governments would think it was their job), so what kind of defense is Sealand, or HavenCo in particular going to have in place if any?

    -Tommy

    --
    "I got a half gallon of Jack, and 2 dozen Ant Traps. I'm about to get wild." -me
  21. What will you do WHEN you get shut down? by joshamania · · Score: 5

    I haven't seen this question yet, so now I ask. In order to do the proper due dililgence on this matter, I would like to know what you will do when you get shut down? I don't think it likely at all that the UK will not take a serious look at what you are doing and disagree with it. They are not going to allow you to operate within their territorial claim and not be subject to their laws. Period.

    I've read that you have plans for other locations, but the information was very vague (as is this question ;). What do you plan to do when, either the UK invades, the US invades (highly likely from where I sit, there are entirely too many people in this country that think that my business is their business), or some non-governmental organization invades? Why wouldn't some unscrupulous individual bent on corporate espionage and blackmail just hire some mercenaries and come steal your servers?

    I love the idea, but this is just ridiculous. Unless you've got unlimited capital coming out of your ears, this is not going to happen. Even if the governments leave the physical location alone, they are bound to shut off your land lines. Satellite bandwidth is beyond prohibitively expensive right now and will remain so for many years. Do you plan to launch your own satellite and man your own ground station in some secret location in order to maintain connenctivity? Even that wouldn't be enough. Governments would find that and shut it down too...

  22. Physical Security by Crazy+Man+on+Fire · · Score: 4

    clearly, you folks are in a highly secure location, and can protect your data and hardware from unwanted access. however, what measures do you have in place to protect yourselves from hostile (physical) invasion? considering your unstable relationship with the british government and how the mpaa convinced the sweedish government to raid a kid's house for the decss thing, what is to stop some sort of military/police infiltration of your facility if somebody decides that you are hosting something they don't like?

  23. Physical assault & freenet by revscat · · Score: 4

    1) There is a not-all-that-slim chance that if activities began to occur on your data haven that the Western powers disagreed with, they would find a way to excuse an invasion and confiscate your equipment. The obvious wrong answer to this would be to build your own defense. Is such an invasion even a conern for you? Have you given any thought to signing treaties or other such matters of statecraft, or do you think the international community doesn't take you seriously enough to consider such offers?

    2) Second, with the coming of sites such as Freenet, do you feel that a data haven such as you have envisioned is still necessary?

    - Rev.
  24. platforms and access by felix · · Score: 4

    I'm curious to know what platform or platforms you will be running your service off of? My guess would be something like openBSD and solaris w/ some microsoft scattered about for customer compatibility, but what do I know?

    Also how will clients access their files and how will those files be stored? Will you be using existing technology now like ssh/https type for the transfer or will you be writing a secure client?

    Thanks.

  25. Single Point of Failure? by Local+Loop · · Score: 3

    I was wondering if you have multiple internet backbone connections. I read something about a microwave link to the mainland, but no details.

    Do you have multiple microwave links?

    Do you have connections to multiple countries, so the UK can't just shut down your connection?

    What is your primary source of electrical power, and how long can you operate with backup power when that fails?

    Best Regards,

    Local Loop

  26. Why do you need physical security at all? by Jamie+Zawinski · · Score: 5

    Lots of people are asking questions about physical security, and how you're going to repel missiles and commandos, but I've got the opposite question: why do you need physical security and a physical location at all? Would not the best way to protect your customers' data be to wrap it in hard crypto and distribute it far and wide across the whole of the net, ensuring that there is not a single point of failure or a single physical installation that can be isolated?

    As we've seen again and again recently, the best protection against censorship and other legal attacks is massive redundancy and decentralization.

  27. International Affairs by panda · · Score: 5

    According to the Sealand Government web site, Havenco "will now take over operations of the government of Sealand." As I understand the other text on the same page, it is generally believed that the government of the UK would not interfere in any acts of piracy, terrorism, or assault on your "territory." Since you are now within the limits of the territorial waters claimed by the UK, you probably won't have to worry about a full-out assault from a sovereign nation, but another attack like that of 1978 could happen again. Of course, there is nothing but a few court rulings to protect you from Her Majesty's Armed Forces.

    Given the precarious nature of the "sovereignty" of Sealand, will you be seeking international recognition and treaties to guarantee your physical security from such attacks? Will you be joining any of the international protocols for cooperation in law enforcement or other areas? I would think that joining these would go a long way to cementing your viability.

    --
    Just be sure to wear the gold uniform when you beam down -- you know what happens when you wear the red one.
  28. Is this site permitted? by broody · · Score: 5

    After reading your TOS I have become rather curious in regards to the following cluase:

    Unacceptable publications include, but are not limited to:

    1. Material that is ruled unlawful in the jurisdiction of the originating server (Such as child pornography, in the case of our flagship Sealand datacenter)

    In the case of the Sealand datacenter, what are some of the limitations?

    Please note that in the following examples I am not equating one example with any other or implying that any of the following should be censored; rather they are examples of what I would consider sticky wickets when running a "data haven" and wonder how such things will be handled.

    Imagine the following:

    I am a rabid anti-choice activist in the United States. I wish to post a site with a hit list of doctors performing abortions in the United States. After each "accident" I wish to mark them with a big red X. I publish detailed information on how to find each of these doctors.

    Is this site permitted?

    I am a hacker who wants to play DVDs on my Linux box and I want to use free software. I want to place source code on my website. The United States says this violates some stupid law and some annoying people object.

    Is this site permitted?

    I am a devote Iron Chef fan and Fuji TV has just sent me a cease and desist order. I wish to move my materials to Sealand.

    Is this site permitted?

    I am a regular guy in the UK creating a website about my daily life. Some people don't like the way I talk about them and my site is pulled.

    Is this site permitted?

    Will you allow sites advocating the overthrow of rival goverments, challenged uses of intellectual property, bomb making instructions, and other information that will get other nation-states panties in a twist?

    --
    ~~ What's stopping you?
  29. Points of Contact to the Internet by gregor_b_dramkin · · Score: 5
    What will you do when pressure is exerted on your landlubber ISP to shutdown your connection? Move to another ISP? What happens when no one else will give you bandwidth? A renegade server farm doesn't do any good if no router will accept its traffic.

    Don't say it can't/won't happen. Unfortunately, it can and probably will.

    --
    You can never equivocate too much.
  30. Security by MenTaLguY · · Score: 4

    How, generally speaking, are you handling physical security at Sealand? Private guards and/or hired mercenaries, evil high-tech lazer defense systems, rabid dogs with bees in their mouths so that when they bark they shoot bees at you, what?

    I mean, Sealand's already been taken by military force once, and back then it didn't even have anything more interesting on it than a self-proclaimed prince, his wife, and their heir apparent.

    Now, you've got some very very valuable data to protect, and while the equipment may theoretically be tamper-proofed, I would hope that that is not your _only_ assurance of security.

    I'm not talking about full-blown military incursions, either ... I'm sure the UK will look after you in that regard. Specifically, are you prepared for a businessman bringing in a private mercenary force? It's happened before, after all.

    --

    DNA just wants to be free...
  31. Liability of your service provider by Anonymous Coward · · Score: 3
    It seems as though part of the service you provide is the ability to maintain Internet services unfettered by normal government restrictions (ala, DMCA, etc.).

    What company is providing *you* with networking on Sealand? Is it possible that they could be liable under the laws in their own country for traffic coming out of Sealand? It's possible that this could negate any benefit to setting up a Sealand server.

  32. Questions by DigiEbola · · Score: 3

    Several come to mind... First, is Havenco hiring? It would be cool to work in a datahaven. Second of all what would HavenCo do if all of their outside access was cut off, either by hostile intent or by bureaucratic nonsense? Pretty neat, if you can keep other people from trying to regulate you or put you out of business.

    --
    Network penetration is network engineering, in reverse.
  33. Web Email (was: Re:Disconnected Living) by xyzzy · · Score: 5

    Ooo! The more interesting question to ask is:

    Can I get (either for free, or since this is a business, for pay) an email address at havenco.com, or some other domain hosted at Sealand?

    In reality, the most important data any person or organization has is their email! It can be read, spied on, subpoenaed, etc. I'd pay MONEY for this service.

    Will Sealand be getting a top-level country code? If so, you could also sell domains, but let me say that I think the hottest idea is selling web-based email accounts.

    Dibs on "billg@havenco.com" :-)

  34. How far will you go? by krog · · Score: 3
    hiya, rdl...

    I'm sure you know the extent of what you're getting into. This data haven represents an international "threat" to security/intelligence, a threat that sooner or later I expect a country's intelligence agency will choose to deal with.

    My question is: how far are you willing to go with this data haven? It seems to mean much more to you than just a cool networking phenomenon; are you willing to fight and even die for these ideals?

    -peeto

  35. what does it offer? by mikpos · · Score: 4

    You say in the FAQ that you won't store things which are illegal in the client's country. It seems to me like one of the most important attributes of a data haven would be its ability to let people escape oppresive governments. If they can't do this, then what are they gaining by going to you with their data?

  36. Disconnected Living in a Connected Business by Amoeba+Protozoa · · Score: 5

    Setting up a company on a remote island, even one that doesn't require a lot of on-site workers, was undoubtably difficult.

    What were the major challenges of setting up on the island? How many people, and what sort of equipment did it take? Is there more left to do?

    What are some of your day-to-day facilities like (food, shelter, perhaps even recreation)?

    What is your daily cash burn rate? Are there ways to cut it?

    Are you making a profit now? If not, when do you plan to be able to?

    Do you have a plan in case of a hostile take-over?

    Where can I send my resume? :)

    Interesting concept...I wish you luck!

    -AP