• Free CIO-level whitepapers



    [ad] Check out these whitepapers published by IDC and HP to help you make tough decisions about your IT environment.

    Leveraging the Always On support experience for IT transformation: This IDC whitepaper outlines the importance of support services in IT environments. IT organisations are now required to support everything from legacy systems and storage to virtualised configurations and cloud-based computing in complex, heterogeneous environments. The increasingly critical role of vendor-supplied external support services is discussed and highlighted in addressing these emerging IT environments going forward.

    Conquering the challenges of data center complexity: Virtualisation and cloud are two popular IT trends that lower costs and make computing more secure and efficient. However, they also add complexity. Read this thought leadership paper and learn new ways to conquer your data center complexity challenges.

  • Great articles on other sites
  • RSS Delicious/delimiterau


  • Save up to $200 on ThinkPad laptops



    [ad] Lenovo ThinkPad Edge laptops boast best-in-class voice and video conferencing capabilities to help you stay in touch and HDMI, stereo speakers and a HD screen to keep you entertained on-the-go. Grab this coupon and save up to $200 each on each laptop.

  • 5 months FREE on phone system rental



    [ad] Rent a new phone system and connect your phone lines with Commander to receive 5 months rent free. Why rent with Commander?

    -Tailored complete solutions
    -Great offers from leading phone system brands
    -Rental & communication on a single bill
    -Renting systems conserves cash flow

    Hurry – act before 30 June!
  • News - Written by on Friday, July 1, 2011 10:47 - 17 Comments

    Don’t let the FBI steal your server, says Ninefold

    blog Fledgling Australian cloud computing startup Ninefold has so far played relatively nice when it comes to the jurisdictional debate about where data should be stored, politely making its way amongst the likes of Amazon, Microsoft, Google and so on. But yesterday the company took the gloves off, following a high-profile incident in the US which saw the FBI seize a number of servers at the US-based datacentre operated by DigitalOne.

    Writes Ninefold community manager Jonathan Crossfield:

    “What is interesting about this particular incident is that the FBI has such seizure powers at all. DigitalOne wasn’t informed about the raid until three hours after it had begun, and then only because of a call from an employee at the data centre.

    If DigitalOne hadn’t communicated with their customers, affected businesses would have had no idea that their website outage was not down to the usual suspects of technology or error, but instead due to their valuable data sitting in the back of an unmarked black van speeding away from the scene.”

    Crossfield concludes that the same situation could happen in Australia – with ASIO or the Federal Police taking the part of the FBI. However, he adds, at least there might be some more due process around such an event, and you might have a legal leg to stand on in your own jurisdiction.

    Now, frankly, Crossfield’s right. If your data is sensitive, it makes a lot of sense to host it in your own local jurisdiction where you can exercise greater control over it, and clearly the whole existence of a company like Ninefold is predicated on that idea. We’d like to see the global cloud computing players pay more attention to the needs of Australian companies; setting up local infrastructure to support local customers.

    However, of course, that doesn’t mean it’s easy or often even practical to stop using global cloud computing services in general. Ninefold is obviously pushing its own messgae, and the arguments around a number of integrated software stacks — such as the ones provided by Google, Salesforce.com and increasingly, Microsoft (hello, Office 365), means that the global cloud is still going to attract interest, no matter how many servers are seized in the US. That’s life.

    Image credit: FBI

    Related posts:

    1. Winner announcement: Ninefold competition
    2. Patriot Act applies to Amazon Australia, warns Ninefold
    3. Ninefold launches Aussie Box.net rival
    4. Win an iPod Nano and cloud computing credit!
      [Sponsored competition]
    5. Internode has wanted Aussie WoW server for years
    submit to reddit Print Friendly and PDF

    17 Comments

    You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

    1. Posted 01/07/2011 at 10:57 am | Permalink | Reply

      Of course, as Microsoft’s admission yesterday showed, even if the global players open Aussie data centres, the data within it may just be as vulnerable to The USA Patriot Act. So local data from a locally-headquartered company is firming up in the legal debates to be the best and safest bet.

      **Waves from our Sydney headquarters down the road from our Sydney data centre** ;-)

      • Posted 01/07/2011 at 11:22 am | Permalink | Reply

        True, Jonathan, but there are also problems with local companies … for example, Ninefold doesn’t have the ability to offer the same integrated stack of infrastructure and applications which a company like Microsoft does — and from what I’ve seen, local prices are also substantially higher. I believe the cost around data transfer locally is a key obstacle, from what I’ve seen of cloud pricing so far?

        • Posted 01/07/2011 at 11:33 am | Permalink | Reply

          Yes, Aussie bandwidth is more expensive, but then if they open data centres here and want to plug it into the internet, they’ll also have to incorporate that into their pricing model like everyone else does. Of course, being bigger, they may absorb the cost differently, can afford to loss-lead etc. But apples for apples, Aussie bandwidth just costs more no matter who you are.

          And yes, I agree – we don’t have the infrastructure of Microsoft… Got me there…;-)

          Wouldn’t describe that as a ‘problem with local companies’ though. Not everyone wants to go with the big monopoly brand for one thing. Otherwise you’re suggesting any clothing store that isn’t Myer is a problem because they’re not a department store when in reality they all do just fine as smaller businesses with happy customers.

          But these are different issues. Comparing data centres based on their likelihood of being able to protect your data, US-headquartered businesses are at higher risk than local ones and that’s from the mouth of MS.

    2. AM
      Posted 01/07/2011 at 11:00 am | Permalink | Reply

      A curious tick to Telstra hosted Office365 perhaps ;-)

      • Posted 01/07/2011 at 11:20 am | Permalink | Reply

        Office 365 isn’t hosted from a Telstra datacentre … it is purely a marketing and sales arrangement.

    3. thateus
      Posted 01/07/2011 at 5:30 pm | Permalink | Reply

      in a cloud dc it is probably a lot harder to carry away the server as usually there is not a single asset like a traditional rack server. ie big bunch of blades referring to networked storage maybe spread over multiple locations. Fbi etc would have to take the lot!

      these days they probably directly access your portion of the cloud via the provider.

      • Posted 01/07/2011 at 8:18 pm | Permalink | Reply

        That’s a very good point, if servers are removed from a DigitalOne data centre why did the cloud service go down?

        The whole point in a cloud service is that it’s stored online securely and accessible from multiple locations, if one location goes down for whatever reason the other(s) should operate as normal with no obvious impact to the end customer.

    4. Posted 01/07/2011 at 7:05 pm | Permalink | Reply

      If anyone is interested, here are two whitepapers commissioned by Macquarie Telecom about The Cloud and Cross Border (data) Risks, both are PDF documents. They are written by International law firm Freshfields BruckhausDeringer:

      USA – http://slidesha.re/ly8NJc
      Singapore – http://slidesha.re/izwDex

    5. Dean
      Posted 01/07/2011 at 8:30 pm | Permalink | Reply

      Even if Microsoft, Google or whoever opened a data centre in Australia, it doesn’t “protect” you from anything. The reason is, while most of your day-to-day usage of the service would likely be out of the Australian data centre, that’s merely a convenience/performance/latency thing. There’s never any guarantee that your data is stored in a particular data centre, and in fact it’s highly likely that multiple copies of your data would be stored in other data centres around the world anyway — for the purposes of redundancy and resilience.

    6. Posted 01/07/2011 at 10:13 pm | Permalink | Reply

      Westpac have just got around this local data issue by going with Microsoft’s hosted online collaboration solution using a local data centre operated by Fujitsu.

      You are missing a crucial point. If you are an Australian or International company holding any personally identifiable data on Australian citizens you are breaching Australian laws and regulation by moving or making that data available in jurisdictions like USA and Singapore which have laws and regulations weakening the privacy of Australian data. There are also other implications as outlined in the whitepapers such as states being able to tax you even if data simply passes through a jurisdiction. It is your responsibility to be aware of the Australian regulations and laws as to maintaining the security and privacy of data on Australian citizens.

      Thankfully Australia has high standards for privacy and data whereas countries like Singapore don’t really recognise the concept of private data and the USA through the Patriot Act means they can access your data whenever they like and do not have to notify you that they have accessed it.

      So, regardless of what technology can and can’t do and how cloud and virtualisation work, you will be breaching Australian law by not ensuring your data is in a jurisdiction which protects the privacy of Australian citizens data.

      There is absolutely a guarantee that your data is protected when you use Australian data centres.

      • Dean
        Posted 02/07/2011 at 9:38 am | Permalink | Reply

        You are missing a crucial point. If you are an Australian or International company holding any personally identifiable data on Australian citizens you are breaching Australian laws and regulation by moving or making that data available in jurisdictions like USA and Singapore which have laws and regulations weakening the privacy of Australian data.

        Are you suggesting that all of those companies using Google Apps, Amazon’s services or (soon to be) Office 365 are breaking Australian law by doing so?

        Anyway, my comment above wasn’t saying that there were no advantages in going with a small Australia-based cloud provider who only operated data centres in Australia. I was simply saying that even if the bigger providers opened a data centre in Australia, there’d be no advantages for them in terms of jursidiction because they’re not going to keep all of your data in a single data centre anyway.

        • Gareth
          Posted 02/07/2011 at 9:28 pm | Permalink | Reply

          The company I work for specifically signed up our 25,000+ users with Microsoft’s e-mail services because they could guarantee the data was held at their singapore datacenter, whereas Google (which was favoured from a technical POV) insisted all data to be stored in the US.

          I’m sure if either was offering a Australian datastore instead they would have been considered strongly.

      • Thateus
        Posted 02/07/2011 at 9:42 pm | Permalink | Reply

        The geographical location of the DC which “holds your info” is only part of the story in regards data patriotism. Logistically it is pretty difficult for a uninformed third party (law enforcement or criminal) to come into a cloud DC and just take your info. I guess they could take some random disks but even then you’d be hard pressed to get much out of it. It’d be like getting the shredded paperwork from an embassy.

        The real risk – which doesn’t appear to have much media attention – is that hypothetically if you choose a cloud provider which is a multinational law enforcement from other jurisdictions (ie the multiple nations) will have access to your information via the same method that the cloud provider uses to manage your services. It’ll be a lot quicker than just doing a DC raid – and a lot quieter too. The jurisdiction will probably claim that the cloud provider manages that information/operates the asset in that local jurisdiction and thus will need to provide it as per the warrant. Often, such as Google Apps/Gmail, they have a pre-arrangement to access information anyway (http://articles.cnn.com/2010-01-23/opinion/schneier.google.hacking_1_chinese-hackers-access-system-google?_s=PM:OPINION).

        law enforcement will actually LOVE cloud providers as they are usually setup to manage a highly scaled aggregation of logically arranged information – very easy to do searches and haul away data without disruptive raids.

    7. Posted 02/07/2011 at 10:09 am | Permalink | Reply

      If any personal information on Australian citizens as distinguished by the Australian Privacy Act 1988 is being kept or stored in those offshore systems and therefore held in a manner which would breach Australian law and regulations, then yes it will apply to Google Apps, AWS, Office365, Salesforce.com or anyone else. This is specifically why Westpac and others are not using those services in offshore clouds and mandated that the data is specifically stored in Australia (Fujitsu data centre).

      If you (Australian business, government or individual) collects and stores any personal data on Australian citizens you are the defined record keeper of that data and will be liable for ensuring compliance with Australian laws and regulations. This includes company directors.

      Australians have a right to know why information about them is being acquired, and who will see the information. Those in charge of storing the information have obligations to ensure such information is neither lost nor exploited. An Australian will also have the right to access the information unless this is specifically prohibited by law. The specific nature of the US Patriot Act alone is a breach of Australian Privacy Legislation because the U.S. Government can access data on Australians without warrant and without notification. Singapore has similar problems.

      The existing laws are being strengthened even further; a revised Privacy Principle 8, released in an exposure draft in June 2010, creates new requirements for organisations outsourcing data that identifies Australian citizens to offshore data centres. Specifically, Privacy Principle 8 requires that any organisation storing information that identifies Australian citizens in overseas data centres must ensure that the organisation hosting that data offers the same protections as what is stated in Australia’s Privacy Principles.

      Here are some extracts from the whitepapers:

      Any regulated entity and businesses using or storing personal or business sensitive data should exercise particular caution. For example, the Australian Prudential Regulatory Authority (APRA) which oversees the domestic financial services sector, has stated that financial services companies that wish to transfer data offshore must first notify APRA and demonstrate to the regulator that appropriate risk management procedures are in place to protect the data. The company must also secure guarantees in its contract with the data hosting company that APRA will have access to that company to conduct site visits if required.

      Some classes of customer may simply refuse to have their data transmitted and stored overseas. For example, the Commonwealth of Australia Government Contract for IT Services expressly prohibits suppliers from transmitting or storing their customer data outside of Australia.

      Hosting a transactional website on servers in the U.S. can create a taxable presence for U.S. federal income tax purposes. While mere storage of data typically should not amount to the conduct of business within the U.S. for tax purposes, the activity can be treated as the conduct of business if the non-U.S. person stores data for the account of others, or allows customers or other third parties access to the data.

      • Thateus
        Posted 02/07/2011 at 9:43 pm | Permalink | Reply

        Hi – how do the banks etc get away with offshoring all the processing of billing info, service provision to India etc? Privacy laws didnt seem to stop them there.

        PS are you the same Martin Walsh from Macquarie Bank?

    8. Marty
      Posted 20/07/2011 at 11:24 am | Permalink | Reply

      DigitalOne themselves may have breached Section 215 of the USA Patriot Act by informing their customers of the FBI actions…

    Leave a Comment

    Comment

    Get our daily newsletter

    Get our new articles every day by signing up to our daily newsletter.

    Email address:



  • Anonymous tips

    Got some inside information on something that should be made public? Use our anonymous tips form. Even Delimiter won't have a clue as to your real identity.

  • Most Popular Content


  • Three lessons ING's private cloud teaches us
    sponsored post ING Direct recently implemented a private cloud solution to virtualise its entire banking platform, allowing it to provision a new copy of itself -- a so-called 'bank in a box' -- within minutes. Here's three things other organisations can learn from this interesting deployment.
  • Enterprise IT news & views

    • The ABC didn’t sack Bitcoin miner dollar-coin

      The Australian Broadcasting Corporation didn’t fire an un-named IT worker who attempted to use the broadcaster’s vast server infrastructure to make himself a fortune through the Bitcoin virtual currency system, it has emerged, with the employee merely being disciplined and having their access to certain IT systems restricted.

    • Victoria dumps HealthSMART e-health project pills-2

      The Victorian State Government has reportedly decided to walk away from its troubled central electronic health project HealthSMART, which has reached only a limited number of its goals over the past decade since it was initiated, despite soaking up several hundred million dollars worth of government funding.

    • HP completes giant new NSW datacentre 1

      Global technology giant HP has finished building its colossal $119 million new datacentre in Western Sydney and will launch the “world-class” facility next month, with a speech slated to be given by Communications Minister Stephen Conroy.

    • Microsoft beats Salesforce to utility CRM deal microsoft1

      Energy retailer Australian Power & Gas has picked Microsoft’s Dynamics CRM system over rivals Salesforce.com and Right CRM as the base platform for a customer relationship management overhaul to tackle incoming email complaints.

    • NSW finalises colossal datacentre consolidation cableguy

      The New South Wales State Government this week announced the Leighton subsidiary Metronode as the winner of its long-running and wide-ranging datacentre overhaul project, with the company to construct two new substantial facilities which will allow the state to consolidate its IT operations drastically.

    • Two good Australian CIO interviews IT-manager-cio

      There have been a couple of good interviews with Australian chief information officers done by various media outlets over the past couple of days — good enough that we thought them worth highlighting to readers on Delimiter.

    • Three lessons ING’s private cloud teaches us Cloud computing

      If you could provision a new copy of your organisation’s entire internal application environment for development purposes in just ten minutes, and you could do whatever you liked with it, what sort of new systems and processes would you build?

    • SAP considers Aussie datacentre sap1

      The Financial Review has reported that German software giant SAP is likely to build an Australian datacentre to provide services to Australian organisations, should new privacy legislation pass that could affect vendors’ ability to sell cloud computing services locally from global facilities.

  • Enterprise IT, News - May 21, 2012 13:32 - 15 Comments

    The ABC didn’t sack Bitcoin miner

    More In Enterprise IT


    News, Telecommunications - May 21, 2012 10:48 - 4 Comments

    iiNet ramps up Internode digestion

    More In Telecommunications


    Gadgets, News - May 21, 2012 12:32 - 4 Comments

    Galaxy S III listed for Telstra, Optus and Vodafone

    More In Gadgets


    Reviews - May 7, 2012 18:16 - 2 Comments

    Telstra Mobile Wi-Fi 4G: Review

    More In Reviews