Live data from Hacker News

India bans MasterCard from adding new customers

techcrunch.com

31–40 of 180 posts

Re: India bans MasterCard from adding new customers

#31

Data from Indian transactions should be stored and ideally even processed in India. This seems fair and reasonable to me.

What makes it fair and reasonable and does whatever rationale you use here not open up the door to further nativism?

I mean if it is fair and reasonable that Indian transactions should be stored and processed in India, is it not also fair and reasonable that goods sold in India should be made in India, that movies that show in India should be made in India, that all news consumed in India should be written in India?

I get these are not the same, but what is the real difference here? Where does it become unreasonable in my examples and why?

Re: India bans MasterCard from adding new customers

#32
post #31

Data from Indian transactions should be stored and ideally even processed in India. This seems fair and reasonable to me.

What makes it fair and reasonable and does whatever rationale you use here not open up the door to further nativism? I mean if it is fair and reasonable that Indian transactions should be stored and processed in India, is it not also fair and reasonable that goods sold in India should be made in India, that movies that show in India should be made in India, that all news consumed in India should be written in India?…

There is a huge difference to your other examples. The US does not actually have a good track record with protecting their customers with proper privacy laws.

Re: India bans MasterCard from adding new customers

#33

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country.

What do you mean by "properly encrypted"? MasterCard is not going to let you be the sole holder of your encryption keys. And if you aren't holding them, then they they hold it, and then they must be holding in at least one given country. And that country has the power to force them to turn these keys over.

The power to do this is the goal of this game.

Re: India bans MasterCard from adding new customers

#34
The regulations on this has been in play for a while - I remember discussions in fall 2019 on this on asks by indian regulators to all multinational banks, payment processors, etc. The push to segregate local data within national boundaries needs to be addressed soon. Local data meaning transactions between 2 parties within the same country

Re: India bans MasterCard from adding new customers

#35

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country

That encryption is pointlesss. North Korea can just demand the key and decrypt your data (assuming the company has presence in that country). Very few services have true end to end encryption. Currently it's not even feasible for healthcare data (homomorphic encryption is not practical yet).

Re: India bans MasterCard from adding new customers

#36

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country.

How about it gets encrypted same way in North Korea or South Korea. Which one would you prefer?

What if North Korea says it is properly encrypted and gov has no easy access, but we all know that could be just as well wrong?

The U.S. Not exactly enjoys a lot of trust internationally when it comes to customer protection and privacy.

Re: India bans MasterCard from adding new customers

#37

Data from Indian transactions should be stored and ideally even processed in India. This seems fair and reasonable to me.

You think it is fair for companies to be required to run servers in every country they operate in? That seems pretty wasteful and inefficient to me.

Re: India bans MasterCard from adding new customers

#38

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

India wants data residency because it wants to apply its own somewhat unique approach to law enforcement to all digital data — financial and otherwise.

This is a country that switches off mobile data (3G and 4G) at the drop of a hat[1], and switched off an entire state’s mobile Internet access for 18 months[2].

This may appear unnecessary and capricious to some especially in the West. However I’m sure pro-Indian government commenters will say “we’re sovereign, our government can do as it likes as it has a democratic mandate” and that is of course true. And that is, in my view, the driver for India’s interest in data residency. Its laws allow its government an enormous degree of latitude to do what it likes. When it has to access foreign data it is often thwarted by EU or US privacy & legal rules, which it feels is unbecoming of a nation as geopolitically important as India.

What I feel about this is that of course India has the sovereign right to do as it pleases, but its messy, adhoc approach to digital governance won’t win it any laurels and will actually tarnish its reputation. Also, it would be on a much better footing if it passed a decent law on digital privacy, which many have been saying is long overdue — leading to a flourishing unregulated economy in selling Indians’ data[3].

[1] https://www.bbc.co.uk/news/world-asia-india-50819905

[2] https://techcrunch.com/2021/02/05/india-is-restoring-4g-inte...

[3] https://restofworld.org/2020/all-the-data-fit-to-sell/

Re: India bans MasterCard from adding new customers

#40

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

All data is capable of being decrypted somewhere. Usually where you are storing it. Otherwise you can't do anything with it.

Storing data encryped in north korea, with the capability to fetch and decrypt that data in Sweden, is approximately equivalent to storing the unencrypted data in Sweden (as far as hackers, law enforcement, etc. are concerned), except you've now added the additional risk that north korea only needs to exfiltrate one encryption key to gain access to all your data.

More reasonably, if you're storing the data in north korea, that's also where you have the compute, and therefore the decryption keys, and therefore someone in north korea who knows what they are doing can quitely steal the decryption keys, make a copy of your data, and view all the data unencrypted.

Encryption is only foolproof(ish) when you are sending data between two trusted endpoints. That's not the case for the cloud, the place you are storing the data is also almost always one of the "trusted" endpoints. Encrypting the data at rest has some minor benefits (being a hurdle to accessing the data, meaning that theft of a single hard disk doesn't get data) but doesn't provide any form of unbreakable security.

Post reply on HN