French, German Leaders: Keep European Email Off US Servers
jfruh writes "In her weekly podcast, German Chancellor Angela Merkel said she'd be discussing European email security with French President Francois Hollande. Specifically, in the wake of the NSA spying revelations, the two leaders will try to keep European email off of American servers altogether to avoid snooping. This comes as Merkel's government faces criminal complaints for assisting aspects of the NSA's programs."
You COULD mandate end-to-end encryption if you were really that worried about it. That probably also wouldn't avoid snooping, but it'd make it a bit more difficult. We should probably also move away from using the browser as a mail client. But you're not really worried about snooping, are you? You're just worried about US snooping.
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
The German Prism: Berlin Wants to Spy Too
French officials can monitor internet users in real time under new law
And some of the reports of "NSA spying" were in fact NSA being given phone data from European agencies.
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
> This comes as Merkel's government faces criminal complaints for assisting aspects of the NSA's programs."
> twitter facebook linkedin Share on Google+
My favorite part of the whole thing is that they are facing criminal complaints for assisting the NSA, all while having also been spied on by the very people they assisted. Hmm a happy satisfied feeling from seeing others get what has been coming to them? I believe the Germans just might have a word for that.
"I opened my eyes, and everything went dark again"
You mean if one were to send an email from Munich to Paris, it'd cross the Atlantic and come back?
Depends... Sometimes the German Army brings it directly in person.
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
If you're sending an email from anywhere to anywhere, odds are that at least one or both of you are using an email account with one of the big US-based internet companies (Google, Yahoo, Microsoft, etc.). Or you don't even bother with email and use Facebook instead.
So your message is very likely to not only cross the Atlantic, but also get stored and backed up redundantly in several datacenters including servers in the US. This has nothing to do with internet architecture, just market forces and poor consumer options.
Internet routing only begins to matter to email security if your email account is hosted privately or by a local organization - and even then, you're better off securing the email by encryption than trying to compartmentalize a network that was designed from the beginning to ignore physical locations and borders.
you're not gonna stop us from reading or listening to any of your conversations. We're the proud, the strong, and we own all of your communications :)
You mean if one were to send an email from Munich to Paris, it'd cross the Atlantic and come back?
NSA aside, that's a pretty sucky setup.
It's how the Internet works. To quote directly from the experts: A target's phone call, e-mail or chat will take the cheapest path, not the physically most direct path.
Physical distance is not as important as congestion on the routes. So it might very well be that your data takes a much longer path that what you'd think, simply because it uses the fastest way, not the shortest.
Angela Merkel's approach is pretty idiotic, and it cannot fix the problems. First of all, most emails are routed through the US either because the sender or the recipient has an American email provider (Germans love Gmail, too). Secondly, even if that is not the case, can you be sure that the NSA doesn't spy on traffic in Frankfurt? It wouldn't surprise me.
Only true end-to-end encryption can be a solution. The government in Germany is currently pushing for DE-Mail, which relies on transport encryption only. So that means that your email provider can still snoop and so can the German government, which is probably the reason why they designed it like that in the first place. End-to-end encryption would have been possible, especially since the German government is spending much money rolling out their own PKI, with keys for every citizen right on their new national ID card.
There's a presentation about DE-Mail from last December's Chaos Communication Congress, it's worth watching (video also has an audio track with English translations).
You're looking at it at too low a level. The cheapest route to communicate between two parties is free webmail. Guess which country hosts the largest number of free webmail systems?
You are not alone. This is not normal. None of this is normal.
It's even a law in Canada to prohibe company with data on canadians people to avoid any storage/transport of these data using any IT infrastrure in the USA.
Ceci n'est pas une Signature !