logoalt Hacker News

dannyobrienyesterday at 11:34 PM1 replyview on HN

I'm not sure you were disagreeing with (past) me; but if you were, could you expand on your point?


Replies

kjs3yesterday at 11:51 PM

I'm disagreeing with you. I in the before time, I had all sorts of conversations around this topic with any number of cloud providers that were like:

Us: We are concerned about our citizens (US) data, how are you managing the databases. Clout Provider (CP): They are only managed by fully background check employees. Us: Yeah, but where are they? What is their citizenship? CP: Um...mostly Eastern Europe. Lots in RU. (another CP proudly said "they're pretty much all in China...for cost containment"). Us: ...

Us: We are concerned about our citizens (EU) data, how are you managing encryption? CP: Everything is perfectly encrypted with hardware HSMs and all the FIPS and stuff. Us: So...where are the folks who run the HSMs? CP: Um...mostly SV. Some in the EU. Us: But can you assemble a quorum of US citizens for the HSM? CP: Of course! Us: ...

And on and on. Not to put too fine a point on it, many of us have no faith that vendors self policing international data protection in the face of government level pressure on companies and employees would work. Not that it can't, I don't think it would.

show 1 reply