HN in RSCserver-reason-react
top.mdnew.mdbest.mdask.mdshow.mdjobs.md
← Back to stories

Toronto-Based VPN Provider Plans to Quit Canada over Lawful-Access Bill

141 pointsby speckx 16 hours ago53 comments

Discussion

Loading discussion
  • LorenDB · 14 hours ago

    Problem is, where do you take a company like this if you want peace of mind that the new host country won't immediately try to pass a similar law?

    • recursive · 13 hours ago

      The real use case for satellite-borne data centers.

      • armadyl · 13 hours ago

        I fail to see how a satellite data center would fix this unless the company was entirely off planet

        • recursive · 13 hours ago

          Hell, the whole company could be located on that satellite if it transacts in crypto-currency.

          • dymk · 13 hours ago

            Where do the people live…

            • recursive · 12 hours ago

              This wouldn't work for companies that require humans for now.

          • bluGill · 13 hours ago

            Despite the hype, crypto is traceable. It is harder than other currencies and one transaction is probably untraceable. However if you are running a business you are going to get repeated payments from customers and repeatedly pay your employees and suppliers, which in turn creates enough data that they can track you down.

            • blakeashleyjr · 12 hours ago

              Mullvad accepts Monero (XMR), the most private and untraceable coin available today. Your point is correct for all others though.

              • cucumber3732842 · 11 hours ago

                Mullvad will accept envelopes of cash. They go far and above any other company when it comes to helping their customers maintain anonymity.

                • mitxela · 11 hours ago

                  Fully legal for any company to do this btw. They just don't want to. Even in the EU, taking XMR payments is legal, or buying things with XMR, or holding XMR - it's only illegal to list on exchanges.

                • bluGill · 9 hours ago

                  In the US, transactions over $10,000 need to be reported regardless. I don't know laws in Europe, but I would expect they have something similar. Which is to say, you can accept envelopes of cash only for relatively small amounts of money before you are going to get in trouble yourself. The government doesn't like tax fraud, and without the ability to trace things, they can prove tax fraud just because if there was no tax fraud, you wouldn't have a certain amount of money.

                  • nom · 8 hours ago

                    i bet that payment option is used very rarely... its brilliant marketing that costs them almost nothing people really like to mention the cash envelope, whoever came up with it is a genius

                    • fwn · 1 hour ago

                      For most people, it is far easier to pay with cash than with Monero. And yes, whoever invented cash was a genius. It's an amazing technology that, in some ways, is far ahead of almost all digital payment systems. OTOH, I did the cash envelope thing only once, out of curiosity. It was fun but now, for convenience, I just buy regular vouchers online.

                  • HWR_14 · 8 hours ago

                    You don't have to report all transactions over $10,000 in cash. Your bank , where you will probably want to keep the money, will report all transaction over $10,000.

          • Onavo · 12 hours ago

            Not possible. If all jurisdictions relinquish their claim over the satellite then it's open to being shot down. The proliferation of space access goes both ways. LEO isn't exactly difficult to reach (many college teams can do it). GEO might work but then you need relays and any relay satellite are essentially tacitly complicit. Satellite (and most aerospace related technologies) are glass cannons. They aren't defensible like a bunker or a tank.

            • rkagerer · 11 hours ago

              What if you had lots and lots and lots of them? Maybe even enough to cause debris problems if they were attacked. With relays into countries that don't overreach their privacy laws.

              • j16sdiz · 10 hours ago

                if you can identify some country that is safe to relay to, why not just put it there?

              • halfcat · 9 hours ago

                > Maybe even enough to cause debris problems Too late https://en.wikipedia.org/wiki/Kessler_syndrome

        • boznz · 10 hours ago

          Not as stupid or far-fetched as it sounds, only now you have to trust a company not a state. There are several companies I would trust with this, but there would be no state I would trust. Some good SciFi which explores this concept (including mine)

      • protocolture · 12 hours ago

        Satellites are very reliant on ground ops. Its much like crypto. You think all your stuff is in space, but the FBI agent has a wrench and will just break your kneecaps until you let him in. But also the FBI agent will pull your operating permit for the country your ground stations are in and take you offline.

      • ninjagoo · 10 hours ago

        > The real use case for satellite-borne data centers. Because of physics and the difficulties of rejecting heat in space, data centers in space aren't going to be a real thing until compute becomes more energy efficient by at least 50x-100x as compared to the present.

    • armadyl · 13 hours ago

      Switzerland? Although they’re attempting to close in on this there too.

      • petcat · 13 hours ago

        Didn't proton end up moving to Germany because of bad Swiss privacy laws?

    • MrDrMcCoy · 13 hours ago

      Iceland.

    • mig39 · 13 hours ago

      How does Mullvad do it? They also have Canadian servers.

    • camkego · 12 hours ago

      How has no one mentioned the Sealand micro nation off the UK?

      • rlpb · 12 hours ago

        It's not relevant. The moment criminality (in the view of other nations with these kinds of laws) hosts itself there, they'll find themselves hauled in front of the UK courts, and find that their "micro nation" isn't recognised and that the UK both claims jurisdiction over them and is able to enforce it.

        • protocolture · 12 hours ago

          The gang gets used as target practice for a Tomahawk missile.

      • mitxela · 11 hours ago

        It's isomorphic to a pirate ship. Just put your nation on a pirate ship, it's the same legal situation but more mobile. Note that pirate means no laws apply to you including the ones that would protect you from things like murder.

      • stephen_g · 9 hours ago

        Sealand is a structure within Britain's territorial waters (since they were expanded in 1987)... From what legal analysis I've seen, a structure just wouldn't ever be considered as a 'nation' in any sense, and if anything happened there that the UK was really concerned about they would remove the occupants anyway... So unless they had a navy that could go up against the UK's... They'd need satellite internet anyway to get connectivity that didn't go through the UK so not going to be great latency.

    • browningstreet · 12 hours ago

      I've been working through my options per digital freedom, human dignity, and non-double-taxation as a US citizen. It's a depressingly short list.

    • zawaideh · 12 hours ago

      Use a VPN from country that is hostile to the one you are living in. This way your own country won’t spy on you. People tend to worry about other countries, but it is usually within the country they live in that they have to worry about their rights being infringed.

      • mitxela · 11 hours ago

        Or use a VPN from some punk who ignores the law. The future belongs to those who say "they can't arrest us all" Except in the USA where they will, in fact, arrest everyone.

        • basilikum · 11 hours ago

          aka your local FBI agent. See ANOM or any of the other honey pots that glowed from kilometers away. And even if they are not backdoored at first, once the state knocks on the developers door with the great offer that their kid will grow up with a father who is not in jail people's principles might change quickly.

      • mikestorrent · 5 hours ago

        Step 1 is making back doors mandatory. Step 2 is banning anything they can't decrypt. I don't know if the second part has been discussed yet, but it's only possible with the former in place, so it makes sense to just ram that in first. Most people don't care about this at all because they cannot fathom what it actually means. It takes the government actually turning on you to understand at a visceral level and by then it's too late. It seems there have still not been enough historical examples of this to truly burn it into memory.

  • elmer2 · 13 hours ago

    Why don't people ever realize that the more Liberal a government is, the more control they will demand from our lives.

    • nxm · 13 hours ago

      They sell "give us more power, we'll protect you" well

    • protocolture · 12 hours ago

      Define "Liberal". I know conservatives love some kinds of control, and centrist/leftist parties love other kinds of control. Swinging from one to the other gets you both, not neither.

      • mitxela · 11 hours ago

        Liberal is basically equivalent to Centrist.

      • blooalien · 11 hours ago

        "Liberal" is anything that "Conservatives" don't like, and vice-versa. To each, the other is "The Devil Incarnate". They're just the two sides of the same extremist political cultist coin. Edit: Yeah, I guess I shoulda expected the downvotes on this one. Too many folks I guess just ain't old enough to remember when both ends of the political spectrum presented themselves as a bit more sane than they do these days.

      • ThrowawayTestr · 9 hours ago

        The Liberal Party of Canada

  • iamnothere · 12 hours ago

    I’m more concerned about OpenBSD. Given how centralized the project governance is, and its base in Canada, I can imagine the government attempting to (for example) force the project to serve backdoored images or updates to targeted people. A backdoor or bugdoor in the source would probably be spotted by someone, and I’m not even sure the bill allows a broad tool like that, but that’s not the only way to compromise software users. Fortunately the mirrors are distributed, so maybe that reduces the risk.

    • wolvoleo · 6 hours ago

      Knowing openbsd and Theo de Raadt I'm sure he will never ever comply with an order like that.

    • walrus01 · 1 hour ago

      Theo has been historically rather uninterested in taking a position on Canadian political issues such as this or engaging as an authoritative voice and source of information with the domestic media and politicians. For instance there is very little if any overlap between Theo and the Munk School's Citizen Lab or associated projects. Or anything that you could broadly classify as an effort parallel to the Citizen Lab. I am not quite sure why this is.

  • singpolyma3 · 12 hours ago

    Didn't this bill get amended to clarify that no encryption back doors are required?

    • EmbarrassedHelp · 12 hours ago

      It was amended to make them less likely, but even the Liberals are saying that it can still be used to target encryption. And the legislation still requires mandatory data retention and interception capabilities for all VPNs, encrypted messaging services, and every other online service.

      • tensor · 11 hours ago

        That's not quite correct. It requires the collection of available metadata only. It does not require that encrypted messages be decrypted, unless the provider holds the keys rather than the user. Still, it's not a great bill. And I guess VPNs are not end to end encrypted. The provider would still be able to access your data if they want to unlike something like Tor. So, it will be the death of privacy focussed VPNs. But presumably things like Signal and Apple's disk encryption will be fine as only the user holds the keys.

        • voxic11 · 6 hours ago

          Signal does a lot to ensure they don't actually know much of what is traditionally considered metadata (like their sealed sender scheme which prevents them from knowing who messages were sent by). Do you know if this bill would require them to roll back those protections?

    • protocolture · 12 hours ago

      If its modelled after the Australian Access and Assistance bill, which it probably is, they will just compel the app to provide the capability to gather the data before/after its encrypted/decrypted, and stream it to some kind of logging device the feds install in your rack.

  • teamspirit · 11 hours ago

    I’m more curious about Tailscale. How would this law, or these types of laws, affect them?

    • snapplebobapple · 10 hours ago

      If I was them I would move my head office to the usa anyway, it's the right choice for most Canadian companies, and pretty much all software companies. it's insane how different the capital markets are for growing businesses in the two countries. I basically stopped Canadian private investing a decade ago because of how stupid it was here.

    • ignoramous · 10 hours ago

      [if they had to comply with the bill as written] Tailscale told The Globe and Mail that it would have to "pursue corporate structures" to distance its international operations from Canada. https://betakit.com/tailscale-windscribe-co-sign-open-letter... / https://archive.vn/899Cm

    • brailsafe · 8 hours ago

      Didn't know Tailscale was Canadian, happy to hear it. Them and Signal are big ones. Signal just because the same bill would threaten their ability to operate in the country.