What are the legal consequences for Microsoft if the US government succeeds in forcing them to bring this data over from Ireland? Won't Microsoft then be in breach of Irish law? What does a company do if forced to choose between breaking one of two legal instructions? Perhaps they can just choose?
Alternatively, the Irish Microsoft corporation could decide to prevent the US corporation from having access. It could be argued that they are legally required to do this. Then the US corporation can say they no longer have access. It doesn't matter that the US corporation is the only / majority shareholder because the shareholders cannot compel the company officers to do something illegal (i.e. provide access).
I guess the US government will force the US based part of Microsoft to cooperate. No choice, possible in stealth. This might or might not be discovered by the Irish part/government, which must then sue.
Basically there is no winning for Microsoft, except keeping it secret, having the US government pressure the Irish not to sue, or having the NSA pay possible fines.
Its not really that simple, since Ireland is part of the European union. If Microsoft willingly break data protection laws, then the EU court would likely sue Microsoft again.
Given the history of EU court vs Microsoft, and the market size of EU vs US, Microsoft has no easy solution to the problem. The US government might pressure the Irish, but would have a harder time against European union (which I suppose is part of its design).
Sadly, so far no company has been sued by EU for complying with american legal requests.
I think the motivation is somewhat along the lines that the company didn't have a choice in the matter. Personally I wish that didn't matter and that the privacy breaches would have been prosecuted - I can think of nothing that makes legislative changes faster than companies having to choose where to do business because it would not be possible to do business both in USA and EU.
There have been some very shady dealings between Europe and the US, in areas as sensitive as financial and travel information, where it seems the US has demanded data and Europe has conveniently overlooked and/or hacked its own privacy and data protection laws so they can provide it.
I suspect given the increasingly anti-EU sentiments in many European countries and the outright hostile behaviour of the US toward foreign citizens in recent years, this situation isn't going to last much longer. Someone in politics is just waiting to make their career by telling a weakened EU administration and/or the US where to go, presenting themselves as the people's advocate and defender of basic human rights. This issue provides a convenient and potentially very effective vehicle for anyone with such ambitions.
Put another way, the asymmetric legal, economic and diplomatic relationships that have favoured the US for some time are essentially a bet that the US is worth more as a partner than any cost that asking "how high" will incur. Sooner or later, someone is going to call them, and at this point I'm not sure whether they're just bluffing.
I think I would agree to what you are saying as to the logical conclusion of what is happening now, but I hope no one will conflate such a possible outcome with it's probable effectiveness as long as the technical capabilities allow for governments, corporations, and individuals to subvert such systems.
Would citizens of the EU have faith in such a candidate anyway who will basically play the same game as their predecessors? Would anyone with the technical capabilities to develop and use encryption/steganography software for things they deem necessary to encrypt, put any trust in such a candidate over themselves?
Seems like a growing market to sell people on privacy as a service, which means there will be a growing market for those who want to subvert such…
Firstly, the means to make mass surveillance significantly more difficult and expensive already exist, we just don't use them routinely as a society. This lack of security and privacy awareness is harmful for many reasons, only a few of which are related to potential abuses by government organisations, but part of the reason they haven't been used more is because of the pressures imposed formally and no doubt less formally by governments. There is always going to be a balance here, because obviously there are bad people in the world and governments are expected (reasonably or otherwise) to protect their citizens and organisations against those bad people. I doubt any government is going to willingly give up all possibilities to intercept communication, but I think you could have a situation with much more transparency and oversight than we have today to keep that power in check and directed to its intended purposes.
Secondly, one of the most disappointing things about this whole affair is that our own intelligence and security services (I'm in the UK) seem to be more concerned with covering their backsides and keeping tight with their US chums than they are with actually, you know, providing for the security of their own country. In an era when foreign surveillance is a significant threat to everyone and so-called allies are among the prime culprits, the duty of our services is to treat those allies as hostile to the extent that their observed behaviour demonstrates they are hostile, and to respond proportionately. US spying on all our citizens' data? Promote encryption as standard and advise businesses on how to keep their data out of US jurisdiction. If allies have legitimate grounds for wanting sensitive information about British people (and I'm certainly not saying they won't have legitimate grounds for doing so from time to time) then let them request that information through proper channels and in compliance with our laws (and make sure our laws provide for assisting allies appropriately but with appropriate controls and oversight as well).
Ultimately, you can't rationally expect governments to protect their people without allowing them to use the technical tools and legal powers necessary to do so, but neither can you rationally protect your society and way of life by destroying it. This debate is all about resolving that inherent conflict in as fair and practical a way as possible, and to that extent, I think some fresh views in politics could improve the current situation considerably.
Firstly, the means to make mass surveillance significantly more difficult and expensive already exist, we just don't use them routinely as a society[…]but I think you could have a situation with much more transparency and oversight than we have today to keep that power in check and directed to its intended purposes.
One has to acknowledge that it is also not presently in the interests of those who have kept it so. Transparency is a two way street, if everyone as individuals had access to such information that is in the hands of the few to leverage, many aspects of our society could also be made better. After all, "encrypt all the things" makes one wonder about the effort exerted is worth it all, especially if it enables individuals to deceive/mislead/exaggerate to others in the name of privacy.
Secondly, one of the most disappointing things about this whole affair is that our own intelligence and security services (I'm in the UK) seem to be more concerned with covering their backsides and keeping tight with their US chums than they are with actually, you know, providing for the security of their own country.
I question how much "security" there needs to be when governments, corporations and individuals go to such lengths to hide such information from others to maintain the asymmetry of information from individuals of the public, and wonder if they're would be more "security" provided if the public who funds such boondoggles had access to such infrastructure. I'd rather have API keys than the hand-waving/profiteering/"we know whats best for you" media/policy makers and it's enablers tell us what they think we, the public, should know of what they do on our behalf, because only they should be responsible for protecting us, and not ourselves as individuals?
I never have expected any government to protect "their" people, when all of them to some degree are actively harming them and continue to do so through various means unaccountably with claims onto behalf of the public.
Just in case it wasn't clear, when I wrote "providing for the security of their own country", I was referring to protecting their own citizens and organisations from unjustified mass surveillance by foreign powers (whether or not those powers purport to be allies). If the press releases and government statements are any indication, there seems to be more emphasis right now on collaborating with those foreign powers and even helping them to conduct their surveillance than in reining them in or applying technological measures to prevent or deter acts that are not permitted under our laws.
Part of Microsoft's solution to the problem is getting this headline published. While the article suggests that this has been going on since before the Snowden information disclosures arose, demonstrating that they're resisting is a change from the perception many had regarding Microsoft's stance on these issues when the Snowden content first began to be published. This excerpt supports this point:
"Microsoft’s efforts to push back against the government in this and other cases, company officials say, predate the disclosures by former National Security Agency contractor Edward Snowden about the reach of U.S. surveillance. But the revelations, which began a year ago, “certainly put a premium on demonstrating to people that we are fighting,” said one Microsoft official who spoke on the condition of anonymity because he was not authorized to speak for the company."
That is an important point. The ironically named Patriot Act contains a deeper, clandestine layer a Treason Act, if you will, that can compel American companies to act in ways that are illegal in other jurisdiction. It is kept secret and any business costs and consequences for those actions are compensated, also clandestinely; which is also the biggest reason why it is actually quite crucial that American companies are not trusted by other people around the world.
If, e.g., Europe, is serious about protecting and defending against the demons that are quickly consuming the USA; they need to put in place meaningful, positive controls in place.
We really need to start coming to terms with the fact that we, the USA, are quickly becoming or maybe even are the most dangerous force humanity has ever seen. Sure, we are not "doing anything wrong" other than killing civilians and even out own people against our own laws by rationalizing ways and reasons to sidestep our most core fundamentals; but we will all rue the day that the force canalizes and stripps off its mask to reveal something far more sinister than most people could even imagine.
You have to remember, no horrible regime took power by saying they will graduate to brutalizing their own people. Put it this way, we are well into several meth highs, still insisting that we will be able to stop when we want to and control any addiction that may arise.
Suppose the people working in the US are required to tell the people in Ireland to give over the data, and the people in Ireland are required to refuse. Maybe they'd just have to have a really long argument on the phone until the court got tired of it.
And if the people in the EU complied, they should similarly be held accountable under EU privacy and data protection rules. Either way, Microsoft and/or their employees personally wind up in serious legal trouble.
This is why Microsoft are in a Catch-22 situation, and why the correct solution for Europe is probably to just stand their ground until the US realises it has gone too far in expecting its laws to apply to the whole world and is now asking the impossible at the expense of its own business community.
Is it really an "internal" structure though - Microsoft US and Microsoft Ireland will be different legal entities. Of course, Microsoft US as the owner of Microsoft Ireland can tell their subsidiary to do something - but that doesn't mean that the management there will do it if it is illegal.
Presumably there is a way to challenge this though. If the court ordered Microsoft to produce a square circle could they still be found in contempt for failing to do so?
If companies like Microsoft adopted end-to-end encryption wherever they can for their services, this would be less and less of an issue. The users from a certain country wouldn't need to "trust Microsoft" anymore then, because there would be nothing to trust them with. In the same fashion, governments wouldn't need to try and force Microsoft to build local datacenters to keep the data there. When the service is trust-less, such policies aren't necessary.
Fair point. I was more meaning that arguments about how he couldn't comply (in that case for legal more than technical reasons) didn't cut much ice. The general view of the authorities appeared to be that the operator of the service was required to comply and if they hadn't left themselves a way to do so without violating some other obligation then that was their problem.
But if there was technically nothing they could do to access the data, they could not be forced to do it. If I encrypt data on my machine and upload it to s3, Amazon cannot be forced to do anything other than provide the encrypted data to the government. They can't be compelled to give my key because they do not have it. It is very hard to operate e-mail this way, because the server cannot send your e-mail other servers in the encrypted form, unless you limit correspondence to users that are using your encryption and key-exchange system.
Not all cloud services have this limitation. However I suspect that there will always be some metadata that the government will be able to request from the cloud provider, and this legal question will still be relevant.
I would think Microsoft has the upper hand untimely. They could always take the nuclear option and stop selling the government windows or something drastic like that.
Alternatively, the Irish Microsoft corporation could decide to prevent the US corporation from having access. It could be argued that they are legally required to do this. Then the US corporation can say they no longer have access. It doesn't matter that the US corporation is the only / majority shareholder because the shareholders cannot compel the company officers to do something illegal (i.e. provide access).