The Forrester note† that the article links to is a little more balanced that the NYT article. If you don't have time to read the whole thing, here are some good quotes:
It's naive and dangerous to think that the NSA's actions are unique. Nearly every developed nation on the planet has a similar intelligence arm which isn't as forthcoming about its procedures for requesting and gaining access to service provider (and ultimately corporate) data. As stated in the ITIF report, German intelligence has the G10 act which let's them monitor telecommunications traffic without a court order.
The fact of the matter is that the IT services market is a part of our portfolios because it provides capabilities we value either against IT or business metrics. And it's highly likely these values are worth more to you than the potential risk you think your company faces due to government surveillance. And if your company is a prime target for government surveillance, you are probably being watched from within your own firewalls right now.
... you can take actions yourself to protect your data from prying eyes when using these services. A quick tip: bring your own encryption. If you hold the keys the governments can't get to your data by going through your service provider.
For me, it's not about shifting data out of naivety that companies/users aren't being spied on everywhere.
Instead it's about shifting data into a legal domain in which you hope to hold someone to account for intrusive spying.
A non-US entity has zero chance of ever holding the government and agencies of the USA to account. And we're also aware that US companies can be forced by the US government or agencies to access data held (by them) overseas.
But we do have some chance (fractionally above zero, I'm not deluding myself) of holding our own governments and companies within our legal domain to account.
None of it is a substitute to encryption, but this isn't solved through tech alone.
It's not as if government spying prevents anyone else from doing it. And in any case, 'because it's happening anyway' is a terrible argument, you could just as well say that about any crime you care to mention.
Almost all nations have standing armies. But, in isolation, that statement is very deceptive. Only dozens of nations could successfully invade a neighbor. Less than a handful of nations could mount sustained wars across an ocean.
Since surveillance budgets probably track military spending, there are probably many places where surveillance is as ineffective as their military.
But your bottom line is correct: "If you hold the keys the governments can't get to your data by going through your service provider."
Not only are those wise words for users, enabling that way of working, and making security an easy verifiable default is going to be the only way to heal this problem for US tech companies. And they have been slow to get started.
Not only are those wise words for users, enabling that
way of working, and making security an easy verifiable
default, and, is going to be the only way to heal this
problem for US tech companies. And they have been slow
to get started.
The trouble is the service providers have a significant vested interest in having access to your data. Google will never implement a system where only you have access to your data because they make a lot of money by accessing your data.
Depending on where you want to draw the line it would not be a stretch to say that an advertising company like Google would be eliminating their entire revenue stream by implementing such a system.
The reason Google or Microsoft or Yahoo won't implement it is that only on the order of a few thousand people want it. Most people would much rather be able to search their email from any device, which requires the server to have an unencrypted copy.
These companies don't bother with products that have such a niche market. There are plenty of smaller companies that do though, so I don't see anything to complain about.
Sure but unless this new service is along the lines of "I generate my own key pair _and then only ever give Google my public key_" there's no way they're getting me to trust them. And I seriously doubt that's something they are going to try to do, it's to much of a niche market for Google IMO.
Are people no longer clicking on ads? I'm pretty sure Google is still raking the millions and billions it's getting from ad revenue. The environment isn't actually changing.
Hmm this thread is full of people talking about pulling their data off google, so I guess we are talking about longer term viability of free google apps.
What I found most surprising about Germany is that the people here are really insistent on Datenschutz (data protection) and hesitant to e.g. use Google services or Dropbox, while its law enforcement is among the top requesters for data:
How many of the Snowden cables were regarding actions by GCHQ?
If anything intelligence is something that's easier for other states to do as long as you're willing to be less capable than "I could plant a SCADA malware that would slightly affect UF6 production in an airgapped network, in a way that would be irreversibly destructive before it could be detected".
For the rest of what they do, the resource investment costs are far lower than fielding a "real" military, and it's even much easier to find quality amateurs and train them up to professional standards since you don't need 100,000-man armies to have an impact. That's the unpleasant reality of automation for the U.S.; it levels the playing field for the rest of the world.
VUPEN doesn't work in a vacuum after all; I'd be willing to bet the French state itself has quite capable cyber surveillance, attack, etc. capabilities.
> Forrester Research, a technology research firm, said the losses could be as high as $180 billion, or 25 percent of industry revenue, based on the size of the cloud computing, web hosting and outsourcing markets and the worst case for damages.
This was the bit in the Times article that was significant to me.
It will go higher. Then, when people have a choice of veriably secure gear and services from non-US companies, we will see a decline in the "they all do it" posts here.
It's naive and dangerous to think that the NSA's actions are unique. Nearly every developed nation on the planet has a similar intelligence arm which isn't as forthcoming about its procedures for requesting and gaining access to service provider (and ultimately corporate) data. As stated in the ITIF report, German intelligence has the G10 act which let's them monitor telecommunications traffic without a court order.
The fact of the matter is that the IT services market is a part of our portfolios because it provides capabilities we value either against IT or business metrics. And it's highly likely these values are worth more to you than the potential risk you think your company faces due to government surveillance. And if your company is a prime target for government surveillance, you are probably being watched from within your own firewalls right now.
... you can take actions yourself to protect your data from prying eyes when using these services. A quick tip: bring your own encryption. If you hold the keys the governments can't get to your data by going through your service provider.
†http://blogs.forrester.com/james_staten/13-08-14-the_cost_of...