Ask Slashdot: Best Country To Avoid Government Surveillance?
simpz writes: Which country is best to choose for hosting Internet services and locating VMs to avoid government surveillance (both NSA and local)? It should be a country with good connectivity to the US and Europe, but have strong legal protections from mass surveillance. People talk about Switzerland, Norway and Iceland (even Spain). Anyone worked through the pros and cons of each of these? I'm not concerned about legitimate (with court order) surveillance, just the un-targeted mass surveillance most governments seem to do. I don't believe this bad behavior should be rewarded or made easy.
"but have strong legal protections from mass surveillance"
Both the US and the EU have strong legal protections from mass surveillance. The problem is those protections get ignored or subverted.
Your thinking about this the wrong way around.
If you're concerned with surveillance, you shouldn't be thinking in terms of "which country", you should be thinking in terms of "which software".
There's no guarantee that *any* data will be safe *anywhere*. Your best choice, and in fact the only choice with any chance of success, is with a technical solution.
Use strong encryption end-to-end, encrypt any data on the servers, give your clients/customers their keys, and make certain you don't have a back door.
That's the only way to avoid it. Hire some really capable security people to implement a strong system, and employ a security maintenance team to keep you current with known security issues.
For all the bad you can say about Julian Assange, he's an expert in this sort of thing and even *he* wasn't able to choose a good country.
Security through technology, it's the only way.
Most countries fall into one of four categories here: Five Eyes (shares surveillance data with U.S.), 'The West' (same, probably with implicit economic threats involved), Laizzes-faire governments (trivially bribed in order to share surveillance data with U.S.), and totalitarian (keeps the info to themselves but surveils everything openly).
Reporters Without Borders maintains a nice ranking here of countries based on their histories of surveillance and censorship; however, sometimes it turns out that a country high on the list will be revealed to have been engaged in a mass-surveillance scheme all along or has major corruption problems that weren't factored in.
In practical terms, it has always been advised that anything unencrypted sent over the Internet should be assumed to be snooped upon, and now we merely know how true that assumption always was. Your efforts should be put into ensuring everything is encrypted and hashed using secure algorithms that haven't been broken. Even if your server is physically located in Utopia, whose government never does any surveillance, censorship or takedowns, hackers (government or otherwise) from other countries can compromise your server and take all the data or install backdoors to your encryption efforts, so security is more important than location. Of course, a country that doesn't have a history of raiding datacenters hosting certain materials is still a good idea, but don't forget that your upstream hosting providers are one bribe/threat away from pulling your plug unilaterally, so choose them well too.
Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
Instead of asking
"Best Country To Avoid Government Surveillance? "
a question better representing the reality we live in could be
"Least hypocritical country which neither pretends that it is democratic, nor that it never spies on its own citizens"
Muchas Gracias, Señor Edward Snowden !