6 ms·
There is only a single sentence about how this works with US-resident data and foreign intelligence or LE apparatus. I'm under no illusion about the willingnes
by ComputerGuru 10mo ago
There is only a single sentence about how this works with US-resident data and foreign intelligence or LE apparatus.
I'm under no illusion about the willingness of most corporations to hand over everything from subscriber info to content on a dime, but does anyone have any experience with specifics?
Especially pertinent to my question: what is to stop a member of a (non-sanctioned) foreign country (let's say not five eyes) from requesting data on a user of an American service "pursuant to a foreign investigation" (whatever that means)? Does it make a difference in practice if the user is an American resident, a resident of said foreign country, or a resident of a 3rd country altogether?
Example: a dissident launches a website and employs a registrar-provided domain privacy shield (these have notoriously vague guarantees of actual privacy). A "law enforcement officer" from country Xyz "subpoenas" the .com or .tld registry (hosted in the USA) and requests information about the owner of the domain. What happens next (in practice, not in theory)? Do some normally go through US intermediaries? Can American companies just refuse (consider both if the registrar/company has or doesn't have a physical presence in the foreign country in question)?
(Not exactly the same situation, but I was surprised that the FBI request to subpoena the identity of the hero behind the archive.tld service made the news [0]. I a) thought these were very much normal order-of-business things that would happen quietly behind the scenes, b) expected companies would roll over on this info without even a subpoena given the loose guarantees most registrars make about privacy, c) made me wonder if the specific registrars were selected for related reasons, and d) wondered about when and where it makes sense to avoid registering a domain with you real identity even if you use a privacy shield service. Also, I think most companies/registrars wouldn't even bother to notify their customers/users, regardless of whether a gag order was in place or not.)
[0]: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tries-to-unmask-mysterious-founder-of-archive-today/ https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tri...