Week 10 Discussion
The textbook identifies Cloud Computing as one of the “five key trends” for the future of cybersecurity. We could easily spend an entire quarter reading and discussing how cloud computing is affecting cybersecurity, sometimes for better, sometimes for worse. For the last outside reading assignment of the quarter, we are going to look at a current news story involving a very simple element of cloud computing – data storage.
The advantages of cloud storage are pretty obvious, especially in smaller organizations. No more file servers. No more maintaining backups (or worse, not maintaining backups). No more dealing with server crashes. And all of your files are accessible from anywhere. In short, better service for less money. Yes, you are now reliant on the cloud provider, but your organization is likely reliant upon many other companies.
However, there's a legal side to this that is perhaps not quite as obvious. Consider a small medical office. They are required by law to maintain patient records electronically. They can do that in their own office, or they can use the cloud. The cloud has the same benefits for them as for any other business. But they also have to maintain patient privacy according to HIPAA. That puts certain requirements on the cloud provider, which the cloud provider may not satisfy. A simple example is that HIPAA requires certain logs to be maintained and saved. Not all cloud providers will do that.
So that's just an example of a simple legal complication with data storage in the cloud. But it can get much more complicated, and the rest of this week's readings are about some recent news about this topic.
A little background is necessary. The European Union has two “laws” that are relevant to this story.
The first is the European Charter of Fundamental Rights. You can think of this as being roughly equivalent to the United States Bill of Rights, except that it lists many more rights. For instance, there is an explicit right of “Protection of Personal Data”:
“Protection of personal data
1. Everyone has the right to the protection of personal data concerning him or her.
2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.
3. Compliance with these rules shall be subject to control by an independent authority.”
(If you are curious, here's full text of the EU Charter of Fundamental Rights. This is not required reading:
EUCharterOfFundamentalRights.pdf
The other relevant “law” is the European Union's Data Protection Directive, which describes how organizations are required to protect stored personal data.
You can think of the Data Protection Directive as being similar to HIPAA, except that it applies to all personal data. And, to tie this back to storing data in the cloud, if an EU organization stores their data in the cloud, then the cloud provider must also meet the requirements of the Data Protection Directive. And this holds even if the cloud provider is a foreign company, for instance, a company located in the United States.
The United States and the European Union negotiated an agreement known as a Safe Harbor Framework that allows the U.S. government to certify that U.S. companies meet the requirements of the EU's Data Protection Directive. This agreement has been in place for 15 years, though admittedly not without occasional controversy.
The controversies finally came to a head on October 6, when the Court of Justice of the European Union (roughly the equivalent of the U.S. Supreme Court) declared the Safe Harbor agreement to be invalid. This means that as of that moment, all of the U.S. cloud companies that relied upon this agreement (over 5000 companies) could no longer legally operate in the European Union. Administratively, there's a 3 month deadline for the United States to renegotiate the Safe Harbor agreement.
What is fascinating about this decision is that the court didn't invalidate the agreement because of anything any of the U.S. companies have done. The court invalidated the agreement because of the leaks from Edward Snowden, which led the court to find that the U.S. government itself could not be trusted to adhere to the Data Protection Directive, so it did not matter whether individual companies complied.
(If you are curious, here's the official summary of the court's judgment. Again, not required reading: schrems-judgment.pdf
)
So that's the background, here's a few stories from when the CJEU made it's ruling:
http://blogs.cfr.org/cyber/2015/10/07/the-implications-of-the-european-safe-harbor-decision/
A few days later, the U.S. was given a three month timeframe to agree on new data protections:
http://thehill.com/policy/cybersecurity/257203-eu-regulators-give-us-eu-three-months-to-reach-new-privacy-agreement
But not every country in Europe agreed with allowing that three month “extension”. The German government declared that it would not wait three months and would immediately begin to investigate any companies operating under the now invalid agreement.
http://www.infoworld.com/article/2998409/privacy/split-between-eu-privacy-watchdogs-on-safe-harbor-worries-businesses.html
Again, this all came about not because of the actions of the U.S. companies, but because of the actions of the U.S. government.
Microsoft then called on the U.S. government to respect EU privacy laws:
http://fortune.com/2015/10/20/microsoft-data-privacy-steps/
(The full statement from Brad Smith, which is not required reading, can be found at:
https://blogs.microsoft.com/on-the-issues/2015/10/20/the-collapse-of-the-us-eu-safe-harbor-solving-the-new-privacy-rubiks-cube/ )
A few weeks later, Microsoft says it will be building two data centers in Germany. That news got tied in with the Safe Harbor ruling, even though it probably wasn't a direct response to it. For example:
http://money.cnn.com/2015/11/11/technology/microsoft-germany-data-center-privacy/index.html
These are by no means Microsoft's first data centers in Europe. And Microsoft was already involved in an interesting legal case because of one of those data centers.
In 2013, the U.S. Government issued a search warrant to Microsoft ordering the company to provide information from a user's email account. The catch was that the account's info was stored not in the U.S., but in a data center in Ireland. Microsoft appealed the government's order.
I am by no means a legal expert, but ultimately it seems that the legal arguments in the case come down to whether or not the emails actually belong to Microsoft. If they belong to Microsoft, then it is apparently clear that the government can compel Microsoft to provide the emails regardless of where they are stored. But if the emails are the property of the user, then the government may not have that power. Microsoft uses the argument that Microsoft storing of a customer's emails is like a bank storing a customer's property in a safe deposit box:
http://blogs.microsoft.com/on-the-issues/2014/12/08/microsoft-appeal-ponders-u-s-reaction-foreign-data-demand/
The oral arguments for Microsoft's appeal were recently heard, resulting in another series of articles about the case. For instance:
http://thehill.com/policy/technology/253015-microsoft-tests-us-warrant-powers
Why is Microsoft (and pretty much the entire U.S. tech industry) fighting the U.S. Government in these instances? The answer is simple – because they want to be able to provide cloud services to the world. If the rest of the world thinks that the U.S. government will be able to access their stored data, they will be less likely to use services provided by U.S. companies.
And what is the lesson for anybody contemplating storing their data in the cloud? I could flippantly say that the lesson is to use a non-U.S. provider, but that's not true. In fact, it has been pointed out that if you are concerned about NSA spying, there's even less legal protections if your data is stored by a foreign cloud provider. No, I think the only clear message is that the legal system, nationally and internationally, is far behind the technology. And because of that, there is a risk of losing some of the legal control over your data when you make the choice to give up “physical” control.