Where You Are Is Who You Are Even If It Is China

Comment

Image Credits: Filipe Frazao (opens in a new window)

Paul Rosenzweig

Contributor

More posts from Paul Rosenzweig

Editor’s note: Paul Rosenzweig is a senior adviser to The Chertoff Groupa global security advisory firm that advises clients on information security, including cloud computing, and former Deputy Assistant Secretary for Policy at the U.S. Department of Homeland Security

Where your cloud data is stored is, increasingly, critical to determining who controls it. Though many around the globe have become concerned about data storage in the United States, there are worse alternatives. Imagine, for example, if your personal data were stored on a cloud server in China, a nation-state actor well known for conducting cyber espionage against U.S. businesses and surveillance of its own population. Soon, you will not have to imagine any longer – that will be reality.

For the past year, the world of cloud computing has been in a state of turbulence, mostly caused by the various Edward Snowden revelations about American surveillance activities. One of the recurrent topics is the growing requirement for data localization – that is, the idea that data must be stored in a particular geographic location so that it is subject to the laws and jurisdiction of that country. The localization requirement is thought by some to be a way of resisting external surveillance by other nations.

Because of these concerns, there have been proposals in Europe and Brazil to require the domestic storage of data.  In a related effort in the United States, Microsoft is fighting a battle to resist American government efforts to access data stored on Microsoft servers overseas. In short, the trend is, haltingly, toward a rule that where your cloud data is physically stored defines who controls it.

Thus far that battle has, principally, been a struggle within Western countries and couched as a question of law for the benefit of civil liberties and consumer privacy. But that’s not the only reason data storage requirements are being implemented. More authoritarian countries are using data localization to their own ends – as a means of control over civilian populations; continuing the status quo; and maintenance of a despotic monopoly on power. Though Western companies doing business in authoritarian states instinctively resist these requirements, in the end, data localization in a repressive country is often the cost of doing business.

Apple’s recent experience in China is a cautionary tale. According to TechCrunch, Apple has agreed to use Chinese-based servers to store iCloud data in China. In public, Apple put a brave face on the move, asserting that Chinese-based data storage is intended to “increase bandwidth” and “improve performance” for its mainland China customers. Perhaps so. But observers are justifiably skeptical.

The Chinese government, after all, has voiced national security concerns about Apple’s overseas storage of data, raising the specter of NSA surveillance. While a useful sham, these expressed concerns allow China to advance its own domestic policy agenda. Chinese law already requires the domestic storage of local bank and telecom data for security purposes – and as a means of monitoring the domestic population. Apple’s agreement to domesticate its data in China is part of that larger trend.

To be sure, Apple says it encrypts the data that it stores on Chinese telecom servers. But we know that encryption by a cloud service provider is only as effective as its ability to resist government demands for decryption. In Western nations, those demands typically come in the form of legal process where the cloud service provider has an opportunity to protest before a neutral judicial officer. In more despotic systems, like China, the decryption order will often take a more coercive form. Hence the promise of encryption is, at best, a modest road block and, at worst, a chimera.

Apple’s decision is, as a business matter, completely understandable.  When the largest country in the world demands particular structures as a condition of market access, it is unreasonable to expect any corporate actor to resist.

Nevertheless, the consequences of Apple’s move to domestic storage need to be carefully examined. It is already standard policy for most corporate executives traveling to China to leave their personal electronics at home. But until now the concern has been with the surreptitious installation of malicious software and the theft of intellectual property by semi-official government hackers.

Now, for Apple users in China, the architecture of the data storage has cut out the middleman. Data uploaded to the iCloud is vulnerable to exploitation without the need for malicious infiltration. Instead, users who bring their own iPhones or iPads may have their data copied directly from Chinese telecom servers at the behest of the Chinese government.

The vulnerability is particularly acute for U.S. government officials who bring their own devices to China for personal use. The temptation, as always, is the convenience of a readily accessible device. But for the unsuspecting government official, even the compromise of seemingly insignificant personal data can, in the end, have adverse impacts. Sadly, Apple’s decision means that BYOD in China must end.

Whereas China was previously a “wild west” of malicious activity, it is becoming a “closed shop” of digital storage and exploitation. The trend toward data localization increasingly metastasizes into aberrant pathologies that support authoritarian regimes. And, in the end, Internet freedom and privacy suffer.

More TechCrunch

Paris-based Mistral AI, a startup working on open source Large Language Models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

2 hours ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI (unified payments interface) payments rail by one to two years, sources…

India likely to delay UPI market caps in win for PhonePe-Google Pay duopoly

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version of AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO