I want to understand this a bit better from an operational perspective..
Say my DigitalOcean VPS hosted in Germany provides a service X which can be subverted for illegal purposes. Will the police have to me to ask for data or can they go to DO and demand access to the data without my knowledge?
Im not a lawyer, but I assume the laws behind this look pretty much the same in every western country.
I assume that if you want to search/seize somebodies property then you have get a warrant made out the the legal owner of the property. (Obviously you don't have to get a warrant if the owner voluntarily hands out the data...) In your example DO is the legal owner of the server your VPS runs on. I can't see why DO would be required to tell you about it.
I don't know how the owners of data centers play into this. I guess if you have somebody else's property in your possession and the cops have a warrant then you have to hand it to them.
Keep in mind that the actual data on the VPS may be protected by all sorts of privacy laws if, e.g., you run a mail server on it.
Edit: I forgot to mention that the location of the server and the jurisdiction the legal owner is under also play a large role. Also don't forget which jurisdiction you're under. Nobody cares that you've rented a server from a russian company located on the dark side of the moon. In this case they'll probably make the warrant out to you rather than the legal owner. And you'll have to comply.
By this logic, a renter has no right against unlawful searches on their own place of residence. The police just needs to ask the landlord for permission to search a rented property.
I'm just asking, not challenging what you're saying.
Yeah I know. I guess the other extreme would be a rental car or something. I can't imagine the guy currently renting the car being involved in the legal process.
I don't know what happens when a landlord hides weapons or something under the floorboards and then rents the place to somebody. Say the people renting the place are on vacation and the police has a warrant (made out to the landlord in this example). Maybe they can go in with the landlord (and, at least in Germany, they also need an independent witness) but are only allowed to search the actual property and not the stuff in it (because the landlord doesn't own the stuff). I don't know. But this kind of renting is well covered by laws (including lots of laws protecting the renters).
"Renting" a VPS (webspace would be a better example) probably isn't defined by any laws. It feels more like user data connected to a (paid) software service. Renting a dedicated server is a different story.
Actually in most countries there is a lot of laws for landlords and tenants that regulates who is in the possession. A landlord can not just hand out keys to anyone.
Encrypt the shit out of it. My servers are in Amsterdam/Paris.
Is this meant to imply that the legal situation is very different in the Netherlands/France, or that you encrypt everything because it's the same as in Germany?
Regardless of the risk of seizure from law enforcement, I feel you should fully encrypt any remotely hosted servers. There are plenty of examples of datacenter techs being socially engineered to install backdoors, affecting both colo and dedicated. Had it happen to myself with an old server - they called up with some excuse and were able to completely bypass the 2FA in the control panel I thought I was secure with and have the techs disable pubkey authentication and reset the root password.
Yes, the situation is very different. Germany has the strongest privacy laws, Netherlands is practically a police state like the UK, and the French are at war like the US, with special police powers.
Comments
I want to understand this a bit better from an operational perspective..
Say my DigitalOcean VPS hosted in Germany provides a service X which can be subverted for illegal purposes. Will the police have to me to ask for data or can they go to DO and demand access to the data without my knowledge?
Im not a lawyer, but I assume the laws behind this look pretty much the same in every western country.
I assume that if you want to search/seize somebodies property then you have get a warrant made out the the legal owner of the property. (Obviously you don't have to get a warrant if the owner voluntarily hands out the data...) In your example DO is the legal owner of the server your VPS runs on. I can't see why DO would be required to tell you about it.
I don't know how the owners of data centers play into this. I guess if you have somebody else's property in your possession and the cops have a warrant then you have to hand it to them.
Keep in mind that the actual data on the VPS may be protected by all sorts of privacy laws if, e.g., you run a mail server on it.
Edit: I forgot to mention that the location of the server and the jurisdiction the legal owner is under also play a large role. Also don't forget which jurisdiction you're under. Nobody cares that you've rented a server from a russian company located on the dark side of the moon. In this case they'll probably make the warrant out to you rather than the legal owner. And you'll have to comply.
By this logic, a renter has no right against unlawful searches on their own place of residence. The police just needs to ask the landlord for permission to search a rented property.
I'm just asking, not challenging what you're saying.
Yeah I know. I guess the other extreme would be a rental car or something. I can't imagine the guy currently renting the car being involved in the legal process.
I don't know what happens when a landlord hides weapons or something under the floorboards and then rents the place to somebody. Say the people renting the place are on vacation and the police has a warrant (made out to the landlord in this example). Maybe they can go in with the landlord (and, at least in Germany, they also need an independent witness) but are only allowed to search the actual property and not the stuff in it (because the landlord doesn't own the stuff). I don't know. But this kind of renting is well covered by laws (including lots of laws protecting the renters).
"Renting" a VPS (webspace would be a better example) probably isn't defined by any laws. It feels more like user data connected to a (paid) software service. Renting a dedicated server is a different story.
Actually in most countries there is a lot of laws for landlords and tenants that regulates who is in the possession. A landlord can not just hand out keys to anyone.
They can go and ask/seize since it's on German territory. Encrypt the shit out of it. My servers are in Amsterdam/Paris.
Is this meant to imply that the legal situation is very different in the Netherlands/France, or that you encrypt everything because it's the same as in Germany?
Regardless of the risk of seizure from law enforcement, I feel you should fully encrypt any remotely hosted servers. There are plenty of examples of datacenter techs being socially engineered to install backdoors, affecting both colo and dedicated. Had it happen to myself with an old server - they called up with some excuse and were able to completely bypass the 2FA in the control panel I thought I was secure with and have the techs disable pubkey authentication and reset the root password.
Yes, the situation is very different. Germany has the strongest privacy laws, Netherlands is practically a police state like the UK, and the French are at war like the US, with special police powers.