Any legal hoster will have to give up the data to local LEA, eventually.
I would rather go for a hoster that has proven to use encryption and is legally fighting any order they receive.
I don't think a provider should fight any order, especially if the chance of success is low or basically zero. It's also very expensive. A provider that doesn't have the data in the first place, is legally speaking better.
Not every order providers recieve is rightfull or legal or even fullfill the requirements of the law, or the legal forms are just not filled out correctly by the officer or department.
Fighting does not really mean, go to court, that would only really make sense for precedence, but more like "only do as much as you are required by law" and maybe "delay everything as much as you are allowed by law".
Yes, that's reasonable. That's what e.g. mailbox.org does. And they publish periodic reports on how many requests they receive, how many they successfully reject, and how many they have to follow.
But an email provider will have to retain the data unlike VPN companies. Personal details, maybe but there are ways to never share them in the first place but the unencrypted emails are always at risk.
Germany, since I'm a German citizen and know my local rights and laws better than anywhere else. Also easier to take legal action against the company if they they mess up.
One thing is that I email and receive emails from almost no one that uses an encrypted service on their end so I have nearly zero expectations when it comes to email. Regardless, as long as it's encrypted so they have been demonstrated in court to not being able to provide the content of my emails and you can pay with some crypto, then I consider it good enough. Other thing is that regardless of what country you live in, a service outside of the country you live in. Preferably even countries that have the least if not just about no significant information sharing treaties. Maybe hostile to the country I live in is best. I have no concerns about law enforcement in other countries. My concern is the authority that I live under practically every day of the year regardless of their behavior in the present
Other types of services I have higher expectations for privacy like cloud storage and VPNs
Also AFAICT since https://en.wikipedia.org/wiki/HavenCo my understanding is that P2P and distributed technical solutions (torrent, Onion routing, I2P, bitcoin, etc) improved enough that it wasn't really worth it.
In the case of email, security is more important than privacy. The country your provider is based in doesn't matter.
Hypothetically if we were talking about something like a VPN, it would need to be a country which values privacy and which has a vaguely hostile attitude to America. I have no idea what country that would be.
Well, not all EU countries share laws. There's the EU laws, and then there's the countries own laws. We (here in Denmark) is often a bit more secure, than most other countries - and because my provider is in the country I live in, if there are any disputes, they can be settled here, without spending a million on lawyer fees... :-)
Thanks, skimmed through https://www.recordinglaw.com/world-laws/world-data-privacy-laws/denmark-data-privacy-laws/ but it's quite difficult to do a "diff" between one and the other. From reading it I didn't notice significantly better for my normal usage but I'm not a lawyer. It also makes me wonder, if you have done it, how do you know it's not better than say another random EU country also national specific modifications, e.g. Slovenia? Is there any "benchmark" somewhere that identifies which national changes are better?
Are you here to troll, or why do you expect me to teach you on this subject? Seriously, if you need to compare all the laws, be my guest, but don't be daft about it in here.
How is asking to justify a position trolling? You are the one who claimed that Danish law is better than GDPR. I didn't claim you lie or that law elsewhere was better, I solely asked for the proof. It's not because I mistrust you, I just want to learn and you saying it is so without an actual comparison is not enough. If you don't want to help that's perfectly OK you can just say so. It's fine to say you prefer Danish product because they are better and refuse to give proof that it's the case. It won't help me nor others though.
It's the Privacy community on Lemmy, I bet others would love to learn too.
33 Comments
ShortN0te@lemmy.ml · 22 pts · 132d
Any legal hoster will have to give up the data to local LEA, eventually. I would rather go for a hoster that has proven to use encryption and is legally fighting any order they receive.
voxel@feddit.uk · 6 pts · 132d
I don't think a provider should fight any order, especially if the chance of success is low or basically zero. It's also very expensive. A provider that doesn't have the data in the first place, is legally speaking better.
ShortN0te@lemmy.ml · 7 pts · 132d
Not every order providers recieve is rightfull or legal or even fullfill the requirements of the law, or the legal forms are just not filled out correctly by the officer or department.
Fighting does not really mean, go to court, that would only really make sense for precedence, but more like "only do as much as you are required by law" and maybe "delay everything as much as you are allowed by law".
skarn@discuss.tchncs.de · 1 pts · 131d
Yes, that's reasonable. That's what e.g. mailbox.org does. And they publish periodic reports on how many requests they receive, how many they successfully reject, and how many they have to follow.
RogueBanana@piefed.zip · 1 pts · 130d
But an email provider will have to retain the data unlike VPN companies. Personal details, maybe but there are ways to never share them in the first place but the unencrypted emails are always at risk.
voxel@feddit.uk · 8 pts · 132d
Germany, since I'm a German citizen and know my local rights and laws better than anywhere else. Also easier to take legal action against the company if they they mess up.
commander@lemmy.world · 8 pts · 132d
One thing is that I email and receive emails from almost no one that uses an encrypted service on their end so I have nearly zero expectations when it comes to email. Regardless, as long as it's encrypted so they have been demonstrated in court to not being able to provide the content of my emails and you can pay with some crypto, then I consider it good enough. Other thing is that regardless of what country you live in, a service outside of the country you live in. Preferably even countries that have the least if not just about no significant information sharing treaties. Maybe hostile to the country I live in is best. I have no concerns about law enforcement in other countries. My concern is the authority that I live under practically every day of the year regardless of their behavior in the present
Other types of services I have higher expectations for privacy like cloud storage and VPNs
zdhzm2pgp@lemmy.ml · 7 pts · 132d
Iceland, maybe?
akilou@sh.itjust.works · 6 pts · 132d
Sealand!
utopiah@lemmy.ml · 4 pts · 132d
I'm not sure for what matters it makes a difference, namely https://en.wikipedia.org/wiki/Principality_of_Sealand#Legal_status
Also AFAICT since https://en.wikipedia.org/wiki/HavenCo my understanding is that P2P and distributed technical solutions (torrent, Onion routing, I2P, bitcoin, etc) improved enough that it wasn't really worth it.
jacksilver@lemmy.world · 2 pts · 130d
Or space!
I feel like that's the reason people have been talking about space data centers. Once it's up there it's kinda hard to get access to it.
Tenderizer78@lemmy.ml · 6 pts · 132d
In the case of email, security is more important than privacy. The country your provider is based in doesn't matter.
Hypothetically if we were talking about something like a VPN, it would need to be a country which values privacy and which has a vaguely hostile attitude to America. I have no idea what country that would be.
eleitl@lemmy.zip · 6 pts · 132d
My own tamper-proof server in a locked cage. There are no noncompliant jurisdictions.
Core_of_Arden@lemmy.ml · 2 pts · 132d
My own country. It's very transparent here (DK)...
utopiah@lemmy.ml · 0 pts · 132d
Makes me curious, I assume within the EU with GDPR it would be roughly equivalent.
What's the difference between EU countries then and why?
Core_of_Arden@lemmy.ml · 1 pts · 128d
Well, not all EU countries share laws. There's the EU laws, and then there's the countries own laws. We (here in Denmark) is often a bit more secure, than most other countries - and because my provider is in the country I live in, if there are any disputes, they can be settled here, without spending a million on lawyer fees... :-)
utopiah@lemmy.ml · 0 pts · 128d
Which Danish laws go beyond GDPR?
Core_of_Arden@lemmy.ml · 1 pts · 127d
Well, you should read up on the "Databeskyttelsesloven" for one... Or "data protection law"...
utopiah@lemmy.ml · 0 pts · 126d
Thanks, skimmed through https://www.recordinglaw.com/world-laws/world-data-privacy-laws/denmark-data-privacy-laws/ but it's quite difficult to do a "diff" between one and the other. From reading it I didn't notice significantly better for my normal usage but I'm not a lawyer. It also makes me wonder, if you have done it, how do you know it's not better than say another random EU country also national specific modifications, e.g. Slovenia? Is there any "benchmark" somewhere that identifies which national changes are better?
Core_of_Arden@lemmy.ml · 1 pts · 126d
Are you here to troll, or why do you expect me to teach you on this subject? Seriously, if you need to compare all the laws, be my guest, but don't be daft about it in here.
utopiah@lemmy.ml · 1 pts · 126d
How is asking to justify a position trolling? You are the one who claimed that Danish law is better than GDPR. I didn't claim you lie or that law elsewhere was better, I solely asked for the proof. It's not because I mistrust you, I just want to learn and you saying it is so without an actual comparison is not enough. If you don't want to help that's perfectly OK you can just say so. It's fine to say you prefer Danish product because they are better and refuse to give proof that it's the case. It won't help me nor others though.
It's the Privacy community on Lemmy, I bet others would love to learn too.
blimthepixie@lemmy.dbzer0.com · 2 pts · 132d
trashbat.co.ck
DampSquid@feddit.uk · 2 pts · 130d
Bunch of fuckzips
blimthepixie@lemmy.dbzer0.com · 1 pts · 130d
I wasn't sure how many here would get a Nathan Barley reference
DampSquid@feddit.uk · 1 pts · 130d
I still rewatch it every few years, love it!
blimthepixie@lemmy.dbzer0.com · 1 pts · 130d
It's so good.
The guy is also in Benidorm and plays a very different character
versionc@lemmy.world · 1 pts · 132d
HubertManne@piefed.social · 1 pts · 130d
Like geni wish. Because my own country with it treats email the way it treats physical mail most stringently.
MonkderVierte@lemmy.zip · 1 pts · 132d
Why "could"?
racoon@lemmy.ml · 0 pts · 132d
voxel@feddit.uk · 2 pts · 132d
Check out: https://mastodon.social/@delta@chaos.social
sudoer777@lemmy.ml · 0 pts · 132d
Probably some island that hasn't been discovered yet or my own pirate ship, that has the best privacy protections because then I'm the government