Clouded views on privacy

Opinion
Apr 2, 20103 mins

* Yale University and Canadian Privacy Commissioner offer negative -- and misinformed -- views on cloud computing

Privacy and cloud computing have recently been in the news, with stories coming out of academia (Yale University) and government oversight agencies (Canadian Privacy Commissioner). Both, in my view, got it wrong.

First up, and easiest to deal with, is Yale. George Bush’s alma mater recently decided to adopt Google Applications for Education, which would include changing from Horde e-mail to Gmail. (See the Yale Daily News story here.). This IT decision has been roundly denounced by some faculty members, who screamed loud enough to at least postpone the switchover.

Just what were their objections?

“Google stores every piece of data in three centers randomly chosen from the many it operates worldwide in order to guard the company’s ability to recover lost information — but that also makes the data subject to the vagaries of foreign laws and governments,” according to one faculty member. I’d imagine, of course, that the faculty and students currently have no idea where their data is stored, though. Hopefully the IT department has at least a disaster-recovery plan, which includes off-site storage of data.

The faculty member continues: “But even if all data were kept on American soil, Google’s size and visibility as a company makes it more susceptible to attack from individuals, ranging from hackers to company insiders.” I’ll bet you any thing you can name that there are more “black hat” hackers at Yale then on Google’s campus. And, of course, it isn’t the size of the organization that makes it susceptible — but its vulnerability. I’ll also wager Yale has more security holes (because of more decentralized IT services) than Google.

Finally, “Under the proposed switch, Yale might lose control over its data or could seem to endorse Google corporate policy and the large carbon footprint left by the company’s massive data centers.” Anyone entering into a contract for cloud services without explicit contractual language about controlling the data deserves any result that befalls them. And as for the “endorsement,” it’s an argument which has to be far down the list after technical feasibility and security considerations.

Privacy and security are best arrived at through well-negotiated contracts between informed parties, not through the agenda-wielding of ivory tower proselytizers. Well, usually. But, as we’ve learned over and over again, it isn’t the technology that’s the problem — it’s the people and the politics.

Next issue we’ll venture 700 km north of Yale to see how Canada’s Privacy Commissioner tackles the cloud.