How to Securely Host Your Dedicated/VM/Cloud Services including Cryptocurrency

Data on Chinese Dedicated Servers is safer than the US or EU

The most honest thing for me to say, is that if your company is equipped and has strong physical security 24/7, redundant power and redundant internet, you may not even need the services of my company, at least for the physical hosting portion.  This assumes you have 24/7 staff to maintain the network and that you have your own racks, servers, inventory etc… I would argue even if you don’t that this may make more sense to acquire and my company does help consult by both selling and physically managing your on-premises deployment.  But, if you already have the manpower and hardware, you won’t need my company or any company and that is often the best way to go.  There is still the case for off-site diversity, but if you were going to choose a single Cloud provider/Zone, I will argue it is probably fine to self-host your company as many companies have done for a long time.  This also assumes you are in a safe jurisdiction and you have a secondary place to keep that data for redundancy or geo-balanced Kubernetes/Docker Swarm etc..

The reality with a lot of companies is that the ideal situation above does not check all of the boxes, it’s ideal because it’s often not entirely possible.  Thus, most companies often need at least some outside help or hosting.  In that case, you’ll need a trustworthy company, in a trustworthy jurisdiction who has both the technical and legal know how to provide your services securely and privately.  This is something I argue that 99% of companies can’t, won’t and don’t do and is why so many companies and wealthy individuals choose services from people like me.

How can you secure your servers regardless of where they are hosted?

This makes the assumption you haven’t purposely chosen an intelligence or government affiliated or US big tech company, or one under the direction of entities that I’ve described, which I argue is the majority of the tech industry.  I’m assuming you’ve chosen a private and independent company like mine.

I also assume you have a clustered server setup that is like what my company provides, where the drives are completely encrypted.  Once you’ve achieved this and you have full control over the servers, you will have the highest levels of privacy.  The host, not even us, should be able to access or monitor your data, assuming your data is properly encrypted in transit.

At this point assuming your servers are properly secured, the next thing that could threaten you is if somehow someone got your physical SAS/NVME drives and extracted the data but this should not be possible as long as you follow the right procedures to encrypt your data AND you delete the original provider key slot.

Even if your drives and servers were stolen like the EU or US does frequently, they would not have access to your data at this point.  As the provider, we would be unable to comply with any legal order to provide your data since we don’t have access either, only you, the customer has the key.

And if you’ve chosen a company like mine, which is in a secure jurisdiction and ignores frivolous foreign requests, then you’re covered unlike if you were to host in the EU or US, or if you chose an EU or US company that had servers overseas.

The big mistake many make

Some of my friends and clients have done everything wrong with this advice.  I’ve seen companies take what I’ve advised, like above and then they say “OK we’ll choose a EU or US Cloud or Server Provider with servers in Hong Kong”.  This completely defeats any attempt at privacy or stopping frivolous requests, since the US or EU government will just compel your hosting company to tap you and hand over your data.  It doesn’t matter that the servers are hosted overseas when the company itself is either registered in the US or EU or a subsidiary of the EU or US company.

The other thing many people misunderstand is the term “fully encrypted”.  If you aren’t given a key to decrypt the contents of the data and if you can’t control or revoke key access to the data, it means you aren’t secure and your provider is in full control over the encryption.  It would be like saying “my house is secured by 10 keys” but then you’ve given copies of the key to the whole neighbourhood.

Higher levels of protection

To HNW individuals and HNW companies, sometimes they want to take it a step further and have their data stored in a “secret bunker”.  This means we establish an exclusive hosting facility that is completely physical separated from all other clients just for their exclusive use.  The facility and IP space will have no trace to either our company or you as the customer, so it’s not possible to do a scan and for anyone to even find your infrastructure.

Jurisdictions that best refuse US or EU requests

Hong Kong offers the overall easiest system to access and use and is very resistant to foreign requests and even snubbed a US request to seize a $500M USD Russian Yacht.  But if you want one notch higher, then I argue raw data storage in the People’s Republic of China is the ultimate solution.  You can of course still use the method I describe in less safe jurisdiction.  For example we would especially recommend our international clients that host their data in Canada, still have a fully encrypted server service.

Even if you wanted to host in Canada, the US or EU, at least your personal information would be shielded by a company in China.  This means the US cannot subpoena the China company to give out their client information like they would to a domestic US company or use back channels that they have with US big tech.

Mainland China is number one in my opinion for this purpose, because it is actually illegal for a Chinese company to comply with a foreign request by sending data or information overseas without the permission of the Chinese government.

For example Article 36 of the “Data Security Law of the People’s Republic of China” stipulates that any foreign requests by other government or foreign law enforcement, must be approved by the Chinese government.  This is not going to be the case where the US threatens a small EU country or another small country is able to illegal obtain your data through coercion and threats.

This means it is completely illegal for a Chinese company to comply with a foreign data request even by the most powerful foreign governments and intelligence agencies.

Areeb Soo Yasir

Business and technology have always gone hand in hand for me, and now I've built nearly 20 years of expertise. A few notable achievements: -> Tier III-Designed & deployed multiple mission critical datacenter environments in Canada, US, Hong Kong, Singapore & China. -> Software Engineering: Created a Linux OS from scratch, including a custom kernel to maintain millions of dollars in client infrastructure, deploy and report as needed. Created the “Windows Geeks” and “Password Pros” Windows Password Reset software recommended by Microsoft. -> Business Negotiations: Conducted intensive negotiations with branches of the Peoples Republic of China and the various state-run Telecom operations including China Telecom and China Unicom for access to their trillion dollar backbone infrastructure. We were the first western company to have such network access where other IT companies such as Vodafone and Google failed. -> Cloud Infrastructure Creation: Created the first proprietary “Clustered Cloud Architecture” that rivals competing Google, IBM, Microsoft & Alibaba alternatives. I'd love to chat #IT or #Linux or even #Business, so don't hesitate to connect. Cheers!

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *