Live data from Hacker News

India bans MasterCard from adding new customers

techcrunch.com

131–140 of 180 posts

Re: India bans MasterCard from adding new customers

#131
post #6

Earlier quoted context omitted.

The Indian rule seems to require all data be stored strictly inside India, without any of it being stored outside the country. The EU permits data to be transferred outside the EU under a number of circumstances: e.g. if the other country has equivalent data protection laws, if the non-EU company you're transferring the data to has promised to abide by the EU rules, stuff like that. Take this with a grain of salt, of…

Actually the European courts struck down Privacy Shield. So any company transferring data to the US is doing it illegally. Plenty of active lawsuits against google. But as much as HN likes to bash google, people here are pretty submissive when one is asking for advice on legal options against these companies. https://www.bbc.com/news/technology-53418898

> people here are pretty submissive when one is asking for advice on legal options against these companies.

I think to be fair to the HN community on this topic, most of us are not lawyers and shouldn't be providing legal advice. And maybe more importantly, at least in the US, the most rational advice starts with step one being "have at least $500M in a legal fund", which precludes most people from being able to effectively execute a suit against Google.

Re: India bans MasterCard from adding new customers

#132
post #5

So, the reason is that the entirety of the customer data must be stored locally in India, rather than on a server located elsewhere[0]? Does anyone know why the rule in India is so much stricter than the equivalent GDPR rule[1], which allows transfer of data outside the EU in various circumstances (basically if it's assured that it won't lead to the data being subject to much laxer standards of protection)? According…

The GDPR didn’t give a 6 month timeline. And GDPR had a long transparent process that in addition to the official implementation time, gave companies a lot of time to see what sort of rules they would likely be working under even before it was approved. The worst government since liberalization, however, makes capricious rules, without input or deliberations, drops them on the world like they are a JayZ album, and th…

>>> The GDPR didn’t give a 6 month timeline.

This ruling came out in 2018 and they were given an extension until now, 3 years is sufficient enough to implement most things

Re: India bans MasterCard from adding new customers

#133
post #5

So, the reason is that the entirety of the customer data must be stored locally in India, rather than on a server located elsewhere[0]? Does anyone know why the rule in India is so much stricter than the equivalent GDPR rule[1], which allows transfer of data outside the EU in various circumstances (basically if it's assured that it won't lead to the data being subject to much laxer standards of protection)? According…

This applies to a critical infrastructure one of national security.

GDPR is about privacy.

Re: India bans MasterCard from adding new customers

#134

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

I have been a party to some discussion around the laws with mid level government officials and this was a bit like an episode of Yes Minister.

One of the government consultants spoke about "Data sovereignty". When someone asked what it meant he spoke for like 10 minutes without actually answering the question. "Data of Indians must belong to Indians", "Data is the gold of modern world" he then referred to various international reports without actually telling what those reports say.

"We must protect our citizens data" one official said as others nodded in agreement. What they imagined here (I think) was data sitting on a hard drive and protected by people with guns creating a parameter around it.

The files of these regulations moved across many tables and many offices. I am told the real estate companies in India had a big role and influence on these regulations.

Yes, ultimately it is a ridiculous law that does not help anyone. It does not protect anything.

Re: India bans MasterCard from adding new customers

#136
post #66

Earlier quoted context omitted.

India wants data residency because it wants to apply its own somewhat unique approach to law enforcement to all digital data — financial and otherwise. This is a country that switches off mobile data (3G and 4G) at the drop of a hat[1], and switched off an entire state’s mobile Internet access for 18 months [2]. This may appear unnecessary and capricious to some especially in the West. However I’m sure pro-Indian gov…

To expand on this a bit, if you want leverage over companies like MasterCard, Visa, and American Express, it definitely helps to have the data in your jurisdiction. As you noted, they will shut off mobile internet to support the state. If Visa decides that it doesn't want to give the government data on someone's transactions, it helps to have that data in the country. "Oh, but the data is encrypted." Sure, but the co…

> Data residency gives a government willing to bully companies a lot of power. It's simply a lot harder to access information stored abroad and you have a lot less leverage.

You have no clue how much uncontrolled power Indian government has today. This law is brought in to benefit telecom companies and real estate companies. https://www.business-standard.com/article/companies/hiranand...

Re: India bans MasterCard from adding new customers

#137
post #92

Earlier quoted context omitted.

North Korea can demand what it wants. I'm not in North Korea. For North Koreans, all encryption is indeed pointless if the goal is to hide it from the government, regardless of where they want to store data, for this very reason. I can implement true end-to-end encryption in about 30 minutes (only because I gotta look up where I implemented it last). I will encrypt my data using well known and validated libraries, se…

You are moving the goal posts. Of course simple data storage can be made secure, because you have the key. But the article is talking about financial data that is processed by companies. And you mentioned healthcare data, which would also be processed. The companies have the key and they can be forced to hand it over easily. What use is end to end encryption for your healthcare data, if nobody except you can process…

I think the point they are making hinges on the fact that the data just has to be _stored_ there. You can do the processing outside of India, so a company can store the encrypted data in India but process the decrypted data elsewhere.

Re: India bans MasterCard from adding new customers

#138
post #106

Earlier quoted context omitted.

Usually where you're processing it, not where you're storing it. That's when you need to do something with it. Encrypting the data at rest has the major benefit of making its physical location completely irrelevant. Transmitting the data while encrypted has the major benefit of making the physical location of all the nodes through which it passes completely irrelevant. Hence the only thing that matters is the geograp…

Physical location and encryption should be treated as two independent protection requirements, both of which have to be met. Just because something is encrypted doesn't mean it is protected, we already have a few encryption schemes that are no longer considered secure and even if you cannot crack a scheme right now there is always the weak link[1] in the chain. [1] https://xkcd.com/538/

If you used an encryption scheme that is no longer considered secure, the correct response is not to rely on the fact that the server room is under lock and key and your country has, like, really nice laws and stuff. It's to change the encryption scheme.

The XKCD cartoon is another way of stating (part of) my point - it doesn't matter where the stuff is stored (provided you encrypt it properly), what matters is the point at which it can be accessed. A dead owner's encrypted iPhone in the FBI forensics lab is more secure from intrusion by the FBI than an unencrypted hard drive I locked in my basement. Even if I use, like, 10 locks, and they don't (yet) know it's there.

Re: India bans MasterCard from adding new customers

#139
post #118

Earlier quoted context omitted.

Not the state in general, just the ability to create money. The state can still raise funds via taxation, but they need to be more careful in how it is spent, as it cannot be magic'd into existence.

And how would you enforce this if the state continues to have the monopoly on violence? Who would prevent it from banning doing the same thing Roosevelt did in 1933 (banning the private ownership of gold) (of course for crypto currencies they would ban the usage and ownership) or suspending the free market itself like in 1941?

And that is what is so wonderful about Satoshis great invention. The state has far less power over Mathematics, Cryptography and Game Theory.

A gun is useless against ECDSA. A government cannot stop a person holding, saving, spending or transacting in bitcoin. As long as there is a channel, anywhere in the universe that allows submission of valid, signed transactions to peers, the state cannot stop it.

Re: India bans MasterCard from adding new customers

#140
post #106

Earlier quoted context omitted.

Physical location and encryption should be treated as two independent protection requirements, both of which have to be met. Just because something is encrypted doesn't mean it is protected, we already have a few encryption schemes that are no longer considered secure and even if you cannot crack a scheme right now there is always the weak link[1] in the chain. [1] https://xkcd.com/538/

If you used an encryption scheme that is no longer considered secure, the correct response is not to rely on the fact that the server room is under lock and key and your country has, like, really nice laws and stuff. It's to change the encryption scheme. The XKCD cartoon is another way of stating (part of) my point - it doesn't matter where the stuff is stored (provided you encrypt it properly), what matters is the p…

I think the point the parent comment was trying to make was, consider if you are storing data in North Korea; it’s 2010 and your encryption scheme is considered secure.

At some point, North Korea has copied the encrypted data for later data mining.

In 2021 that encryption scheme for some reason is no longer considered secure. Even if you stepped using it in 2014, the data from the time you used it up until you stopped may be compromised.

Post reply on HN