US Unhappy With Australians Storing Data On Australian Shores
Fluffeh writes "The United States' global trade representative has strongly criticized a perceived preference on the part of large Australian organizations for hosting their data on-shore in Australia, claiming it created a significant trade barrier for U.S. technology firms. A number of U.S. companies had expressed concerns that various departments in the Australian Government, namely the Department of Defence had been sending negative messages about cloud providers based outside the country, implying that 'hosting data overseas, including in the United States, by definition entails greater risk and unduly exposes consumers to their data being scrutinized by foreign governments.' Recently, Acting Victorian Privacy Commissioner Anthony Bendall highlighted some of the privacy concerns with cloud computing, particularly in its use by the local government. He said the main problems were the lack of control over stored data and privacy, in overseas cloud service providers."
No, this is typical US attitude. They think they own the world.
If the rest of the world would tell the US to piss off, maybe things could get better. Instead, the US throws their totalitarian weight around and we get bought-off British judges trying to extradite British citizens to the US for conduct that occurred in Britain, between British citizens, that was 100% legal under British law because the US MafiAA wants to try to have the British citizen prosecuted under US fascist law.
Read this article and you'll know why government, private companies, and individuals may not want their data in the "cloud", particularly when you know half of the Internet traffic likely transits through US soil: The NSA Is Building the Country’s Biggest Spy Center (Watch What You Say) http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/
One of the reasons we don't like hosting stuff on American servers is due to one of their laws that the FBI (and similar agencies) can obtain data with a warrant that tells the service (cloud) provider not to tell the customer us. We have our own private cloud infrastructure here in Perth and spread to Adelaide and Sydney with talks of having some in Singapore. We do not want our data on cloud infrastructure we don't manage in another country.
As someone who regularly solutions cloud services for customers, I can assure you, the exact location of the cloud is very important to our big customers. Being able to say it's based out of entirely Canadian datacenters on an entirely Canadian network is a huge advantage over our competitors south of the border. It's not like any of them have been bitten yet, but the perception is that their data is much less safe in another country.
Fuck You.
Shoes for Industry. Shoes for the Dead.
yep. it's amazing the US is complaining here, but then again our country is on a constant downward spiral into idiocy. can't say I'm surprised.
There are really multiple problems...
The US has sufficiently aggressive surveillance and limited privacy protection(and I'm just referring to the stuff that has been declared legal) that it is neither obviously desirable, nor even necessarily possible, for entities in areas with more demanding privacy law to use US-based hosting or storage service.
Second, by the standards of places developed beyond the barter economy, Australia's overseas links are long, not terribly fast, and rather expensive(Also, Telstra...)
Funny how Americans think that since breaking Enigma helped them win the WW2 so much, they are entitled to have the same advantage over the wole world now.
Umm... that movie where US troops secured the vital Enigma machine wasn't actually accurate. It was the Brits who stole the intact Enigma and the brightest of the Brits who cracked the code and, to a large extent, helped them win the war. (OK, having a whole lot of US planes and bombs and ships and tanks and stuff to DO something with the intercepted data was also quite significant, but the intelligence side of things was all down to the Poms.)
You really don't understand the situation. People like me are paid to be paranoid, and to make sure that our company's data is safe from prying eyes as much as absolutely possible (In fact, we are legally responsible for it). I cannot afford to just toss our data out there and not worry about it. My job is to mitigate all of the possible things an outside entity could do to access that data. And fyi, a provider can setup the server such that they cannot read the data on it while still being able to administer the server itself.
And to the trade representative, boo-fucking-hoo. Instead of allowing US companies to guarantee data privacy, even when hosted outside of the country, the Patriot Act forces them to guarantee the opposite. As much as I would like to use a lot of the cloud services out there, I can't just because of that.
In Canada, it is illegal for public agencies or IT companies serving them to store customer/member data on US-operated servers because the Patriot Act contravenes Canadian privacy laws. Many other Canadian associations and businesses have similar policies, because Patriot Act searches would violate their infomration privacy policy.
Where are we going and why are we in a handbasket?
Is there a cloud based company that will not take a peek at any of the information stored on it's servers?
Yes: SpiderOak. They are physically incapable of looking at your data:
Your SpiderOak data is readable to you alone. Most online storage systems only encrypt your data during transmission, meaning anyone with physical access to the servers your data is stored on (such as the company's staff) could have access to it. Or, even if your data is encrypted during storage, your password (or set of encryption keys) is often stored along with your data, thus making its easily decoded by anyone with local access to those servers.
With SpiderOak, you create your password on your own computer -- not on a web form received by SpiderOak servers. Once created, a strong key derivation function is used to generate encryption keys using that password, and no trace of your original password is ever uploaded to SpiderOak with your stored data.
SpiderOak's encryption is comprehensive -- even with physical access to the storage servers, SpiderOak staff cannot know even the names of your files and folders. On the server side, all that SpiderOak staff can see, are sequentially numbered containers of encrypted data.
This means that you alone have responsibility for remembering your password or 'Password Hint' (which you can create to help you remember) allowing SpiderOak to create a true 'zero-knowledge environment' – keeping your data as safe and secure as it can possibly be.
Random Thoughts From A Diseased Mind (Not For Dummies)