Live data from Hacker News

India bans MasterCard from adding new customers

techcrunch.com

81–90 of 180 posts

Re: India bans MasterCard from adding new customers

#81

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

From my understanding (I could be wrong) and why I have to follow all these rules here in Canada, is the USA made a homeland security law in like 2007 that said law enforcement can have access to any foreign individuals data without a warrant/good reason.

So now when picking services I am not allowed to host on any non Canadian servers if we are hosting personal information about staff/users etc. It can be a simple event registration system, survey, or just having to be really careful when using cloud services. I even have to watch out when sharing a innocuous file over Slack.

This really sucked when stuff was moving over to cloud and we wanted to use a lot of hot new stuff, but most providers get it now and provide Canadian servers so not as bad finding compliant vendors.

Re: India bans MasterCard from adding new customers

#82
post #37

Data from Indian transactions should be stored and ideally even processed in India. This seems fair and reasonable to me.

You think it is fair for companies to be required to run servers in every country they operate in? That seems pretty wasteful and inefficient to me.

It's a billion person country.

It might not make sense for every country to demand things like this, but that doesn't mean it doesn't make sense for giant countries too, and it doesn't make it inefficient.

At India's scale costs are already amortized anyways, but worse, consider India's physical location. It's surrounded by hostile nations (Myanmar, China, Pakistan, make a wall around it). To get data out of the country you're talking about moving it through hostile territory, or moving it through vulnerable subsea cables. Not only is the bandwidth probably more wasteful than the extra compute needed to spin up another set of servers to serve the billion people in India, but the network cannot be relied on to keep working during any sort of crisis.

Luxembourg or whatever demanding all data processing happening internally would be meaningfully different. It's less than a million people to amortize over instead of more than a billion. It's next door to allies which the data could reasonably be stored and processed in, instead of isolated. But we're not talking about whether or not Luxembourg should demand this, we're talking about whether or not India should.

Re: India bans MasterCard from adding new customers

#83
post #62
post #6

Earlier quoted context omitted.

The Indian rule seems to require all data be stored strictly inside India, without any of it being stored outside the country. The EU permits data to be transferred outside the EU under a number of circumstances: e.g. if the other country has equivalent data protection laws, if the non-EU company you're transferring the data to has promised to abide by the EU rules, stuff like that. Take this with a grain of salt, of…

Does Indian controlled AJK and Ladakh qualify as "inside India"?

Indian controlled AJK is like two villages in Kargil.

Re: India bans MasterCard from adding new customers

#84

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

> It makes no sense whatsoever, of course.

Silent, bulk, state-mandated surveillance.

Both for the at-home surveillance, as well as to counter the effect of storing it elsewhere, and permitting that state silent, bulk surveillance of the data of your own subjects/citizens.

Re: India bans MasterCard from adding new customers

#85
post #31

Data from Indian transactions should be stored and ideally even processed in India. This seems fair and reasonable to me.

What makes it fair and reasonable and does whatever rationale you use here not open up the door to further nativism? I mean if it is fair and reasonable that Indian transactions should be stored and processed in India, is it not also fair and reasonable that goods sold in India should be made in India, that movies that show in India should be made in India, that all news consumed in India should be written in India?…

There is not a single country in the world where largest bank is not a bank based in that country. Like money, data is something sovereign nations want to control.

EU, China and India all have areas where they want US based firms to store data in a specific way. This isn't changing anytime soon.

Re: India bans MasterCard from adding new customers

#86
post #82
post #37

Earlier quoted context omitted.

You think it is fair for companies to be required to run servers in every country they operate in? That seems pretty wasteful and inefficient to me.

It's a billion person country. It might not make sense for every country to demand things like this, but that doesn't mean it doesn't make sense for giant countries too, and it doesn't make it inefficient. At India's scale costs are already amortized anyways, but worse, consider India's physical location. It's surrounded by hostile nations (Myanmar, China, Pakistan, make a wall around it). To get data out of the coun…

Afaik, Myanmar is not a hostile country. Neither the elected government nor the military dictatorship has animosity at the state level.

Re: India bans MasterCard from adding new customers

#87
post #36

Earlier quoted context omitted.

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. How about it gets encrypted same way in North Korea or South Korea. Which one would you prefer? What if North Korea says it is properly encrypted and gov has no easy access, but we all know that could be just as well wrong? The U.S. Not exactly enjoys a lot of trust internat…

>How about it gets encrypted same way in North Korea or South Korea. Which one would you prefer? Whichever is cheaper and/or more reliable. If I trust encryption, all other answers are bogus. >What if North Korea says it is properly encrypted and gov has no easy access, but we all know that could be just as well wrong? In this scenario, I decide how to encrypt my data. The storage service is just dumb disk space for…

I doubt it would be an option for MasterCard that countries get to decide how they encrypt the related data. But I get your point :)

Re: India bans MasterCard from adding new customers

#88
post #62
post #6

Earlier quoted context omitted.

The Indian rule seems to require all data be stored strictly inside India, without any of it being stored outside the country. The EU permits data to be transferred outside the EU under a number of circumstances: e.g. if the other country has equivalent data protection laws, if the non-EU company you're transferring the data to has promised to abide by the EU rules, stuff like that. Take this with a grain of salt, of…

Does Indian controlled AJK and Ladakh qualify as "inside India"?

Do they have control of the lands you mentioned at present? That's the only reality that counts to make it within the country.

Also, Ladakh is hardly a troubled area from within.

Re: India bans MasterCard from adding new customers

#90

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

India wants data residency because it wants to apply its own somewhat unique approach to law enforcement to all digital data — financial and otherwise. This is a country that switches off mobile data (3G and 4G) at the drop of a hat[1], and switched off an entire state’s mobile Internet access for 18 months [2]. This may appear unnecessary and capricious to some especially in the West. However I’m sure pro-Indian gov…

> leading to a flourishing unregulated economy in selling Indians’ data

At risk of being incredibly inflammatory - this is the first I've heard of bulk Indian citizens' data being worth enough to harvest in the first place - what's changed?

Post reply on HN