Hacker News new | ask | show | jobs
by fterh 2373 days ago
No, you're not misunderstanding. I guess I made that statement with the implicit trust of AWS so I didn't think to qualify it.

You're absolutely right that if AWS is a bad actor it has access to all the information, but I'm working on the assumption that it's more profitable to AWS to be a good actor than bad.

2 comments

> No, you're not misunderstanding. I guess I made that statement with the implicit trust of AWS so I didn't think to qualify it.

But that doesn't change that you are trusting a third party?! I mean, if that were to count as "you don't have to trust a third party", then anything does. Use gmail, so you don't have to trust a third party (except for the implicitly trusted Google)! Use Facebook, so you don't have to trust a third party (except for the implicitly trusted Facebook)!

There is nothing necessarily wrong with trusting any one of those. But then you don't get to claim "no trust in third parties required!"

> You're absolutely right that if AWS is a bad actor it has access to all the information, but I'm working on the assumption that it's more profitable to AWS to be a good actor than bad.

Well, for one, see above. But also: is it? Is it really more profitable to keep your data safe than to give the NSA access and in return get some of the good government contracts, say? Plus, trust isn't just about them not screwing you over intentionally, it's also about incompetence.

I'm working on the assumption that they have a contract with the CIA for hundreds of millions, and likely wouldn't get caught skirting the rules if it suits them - or can buy their way out if they did.