Remix.run Logo
V__ 6 hours ago

For anyone curious, it's the CLOUD act:

> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.

[1] https://en.wikipedia.org/wiki/CLOUD_Act

tzs 11 minutes ago | parent | next [-]

It's weird how everyone focuses on that part of the CLOUD Act. The CLOUD Act actually did two things: (1) that, and (2) provided an expedited way for the US to enter into Mutual Legal Assistance Treaties (MLATs) with other countries.

It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.

The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.

One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.

There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).

So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.

The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.

With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.

There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.

The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing then across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.

For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.

With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.

And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.

The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.

The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.

There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.

Civil rights groups and many others were not impressed with those safeguards.

samudrijan 5 hours ago | parent | prev | next [-]

The point of control is Congress, until we stop electing corpratist politicians, we will continue to get bad legislation.

redserk 2 hours ago | parent [-]

It doesn't matter if it's Congress. At the end of the day America's internal governance systems are America's problem. The rest of the world should not care if a certain branch is causing issues, and frankly, is starting to come to that conclusion.

It's unfortunate for us, but we very rarely isolate individual government systems for other nations.

braiamp 6 hours ago | parent | prev [-]

Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.

kid64 6 hours ago | parent [-]

They're Australian

petcat 5 hours ago | parent | next [-]

Australian companies are also subject to the USA Cloud Act. As is the UK, with Canada coming on board soon too.

Even the entire EU is in the process of negotiating the same agreement.

https://www.justice.gov/archives/opa/pr/united-states-and-ca...

https://www.justice.gov/archives/opa/pr/justice-department-a...

jorvi 3 hours ago | parent | next [-]

That is plain wrong, and on top of that, the CLOUD act doesn't really solve anything because if the order to obtain data is legal for the US arm but illegal for the EU arm, releasing the data from say Ireland to the US would immediately lead to steep monetary and legal penalties for the EU arm.

petcat 2 hours ago | parent [-]

It is not wrong...

You can read the text right here:

https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...

The same agreement is in place with the UK. Canada and EU are currently in the process of negotiating it.

yborg 5 hours ago | parent | prev [-]

Your linked information doesn't indicate anywhere that Australia or any other foreign government is subject to US law. The latter states that negotiation with the EU on this topic was suspended in 2019.

Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty.

petcat 5 hours ago | parent [-]

https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...

> The latter states that negotiation with the EU on this topic was suspended in 2019.

Dated 2023:

> Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations

The negotiations are still ongoing. Canada is further along than the EU.

perpetuallunch 3 hours ago | parent | prev | next [-]

That’s not going to help anyone.

The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence.

https://en.wikipedia.org/wiki/Five_Eyes

JAlexoid 3 hours ago | parent [-]

Even being stored in EU doesn't preclude your data from being targeted by signals intelligence. Which is different than requiring US based companies to provide non-US data to American government.

Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.

wolfi1 5 hours ago | parent | prev [-]

isn't there this five eyes thingy?