Live data from Hacker News

India bans MasterCard from adding new customers

techcrunch.com

161–170 of 180 posts

Re: India bans MasterCard from adding new customers

#161
I am with mastercard on this one. Either they were asked to pay bribe and refused, which is good, or they genuinely care about their customers. In corrupt countries, such as India, politicians and local law “enforcement” love to get their hands in the pockets of honest and hard working people. And what easier way is there than having a card that provides details of the money you have in your pocket.

Re: India bans MasterCard from adding new customers

#162
post #60

All the tech people in this thread arguing how it makes no difference technically where the data resides etc etc. really guys can you not think further than that? It’s simple and obvious the Indian government is exercising total control over its affairs. Naming technical distinctions completely misses the point. This is not a technical issue and has zero to do with tech. It’s political.

Data residency absolutely makes a difference, and I find it stunning that people don't see it. Ok, so you decide to store your nation's sensitive data in another country, $nation. If things get awry, there is a (pretty remote) risk that $nation will break your encryption. But there's also a much less remote risk that $nation will simply block all connections from your country and prevent you from accessing your own d…

Agreed, it’s also also just such an arrogant attitude to take.

People are so steeped in a globalized worldview that they’re unable to appreciate that not everyone considers themselves a “citizen of the world”, and that geopolitics actually do exist.

Re: India bans MasterCard from adding new customers

#163
post #106

Earlier quoted context omitted.

Physical location and encryption should be treated as two independent protection requirements, both of which have to be met. Just because something is encrypted doesn't mean it is protected, we already have a few encryption schemes that are no longer considered secure and even if you cannot crack a scheme right now there is always the weak link[1] in the chain. [1] https://xkcd.com/538/

If you used an encryption scheme that is no longer considered secure, the correct response is not to rely on the fact that the server room is under lock and key and your country has, like, really nice laws and stuff. It's to change the encryption scheme. The XKCD cartoon is another way of stating (part of) my point - it doesn't matter where the stuff is stored (provided you encrypt it properly), what matters is the p…

Only compared to an unencrypted hard drive locked in an American basement.

An unencrypted hard drive stored in a locked Chinese basement is probably quite a bit more secure from FBI intrusion than the encrypted iPhone that they physically possess.

Physical access still matters a lot.

Re: India bans MasterCard from adding new customers

#164

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

"Or am I missing something? "

Jurisdiction is huge thing, not a side show.

Data that sits overseas is subject to entirely different sets of laws which can conflict with local laws.

Those laws also relate to espionage, and even outside the framework of legality ... it matters as well.

It's a lot easier for the NSA to collect data on individuals if it's hosted in the US.

I have absolutely no doubt that financial, legal and health records should simply not leave the local legal jurisdiction without consent and a few more things.

Re: India bans MasterCard from adding new customers

#165
post #40

Earlier quoted context omitted.

All data is capable of being decrypted somewhere. Usually where you are storing it. Otherwise you can't do anything with it. Storing data encryped in north korea, with the capability to fetch and decrypt that data in Sweden, is approximately equivalent to storing the unencrypted data in Sweden (as far as hackers, law enforcement, etc. are concerned), except you've now added the additional risk that north korea only n…

Storing data encryped in north korea, with the capability to fetch and decrypt that data in Sweden, is approximately equivalent to storing the unencrypted data in Sweden Not if there is rate limiting, or other means of preventing the entire set of data being dumped. That is to say, storing it encrypted makes it harder to get the full set of data. Though, I guess in practice the client application would likely be able…

And the whole point of cornering data at rest is that your client can "no longer access it". It's not about the authorities being able to decrypt that data. It's about hurting your business by making it difficult to continue operations.

Re: India bans MasterCard from adding new customers

#166
post #29
post #17

It is good to see India growing as a world power as the largest democracy in the world.

They have been "growing" and "becoming" the next world leader for a while now. Anyone who have lived in india long enough will tell you how far from the truth this is. The only Stick India has, besides their nuclear arsenal, is the size of their domestic market (aka population). I dont think the purchasing power of their domestic market is that lucrative compare to actual superpowers (Economic or Military). Buy just…

> Any sane, rational Indian leader would not be so Anti international investment. (I am not only talking about the incident mentioned in this article, but generally speaking).

FDI has actually increased since Modi became the PM and he was been actively courting foreign companies. I don't understand how he is "Anti international investment".

Re: India bans MasterCard from adding new customers

#167
post #31

Earlier quoted context omitted.

What makes it fair and reasonable and does whatever rationale you use here not open up the door to further nativism? I mean if it is fair and reasonable that Indian transactions should be stored and processed in India, is it not also fair and reasonable that goods sold in India should be made in India, that movies that show in India should be made in India, that all news consumed in India should be written in India?…

There is not a single country in the world where largest bank is not a bank based in that country. Like money, data is something sovereign nations want to control. EU, China and India all have areas where they want US based firms to store data in a specific way. This isn't changing anytime soon.

BCR and BRD, the largest Romanian banks, are owned by Austria and France.

I'd be shocked if most big banks in Eastern Europe are owned locally.

The opposite of what you're saying is true for almost every average or small country, economically.

Re: India bans MasterCard from adding new customers

#168
post #158

Earlier quoted context omitted.

Still not really buying the physical control of data argument. If you need to force a company like MC to comply, you can always solve that problem at the point of sale, or (like they're doing right now) stop banks, which are firmly under your jurisdiction, from issuing cards. A company will hand over data rather than be banned from operating in the country, just the same. The amount of leverage you have with data bei…

As far as I can tell, there's a fair bit of difference between "decreed a crime" and "we've backed up a truck to the DC, and physically seized your data, do as we say if want it back"

What is the long- or medium-term difference, to a company like Mastercard? They want to earn profits in India, they have to comply with the Indian government's demands. Case closed.

Re: India bans MasterCard from adding new customers

#169

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

Will you always be able to access your data stored on North Korean soil? Sure, if it's properly encrypted, the North Korean government may not be able to access it, but nothing's stopping them from cutting you off and holding your data hostage. I used to work for a company that made software for casinos. Many of them were on tribal land, and refused to use any cloud services because they didn't want any of their data…

Well, I wouldn't necessarily only store it on North Korean soil.

Raw data we use for image processing at work (we will miss it if it's gone) is stored in three locations: server room, another server room in a different building, and on the cloud. Properly-as-of-2021-encrypted, of course.

Unless we really fuck something up with securing our storage servers or running a script that accidentally wipes it all at once, it's really hard to imagine a scenario under which all of that is gone at once.

If the cheapest and most reliable cloud storage provider was in North Korea, the only reason I wouldn't use them is the reaction I'd get from Very Important Privacy Peoples when they hear of it. (And also because I don't want to fund a criminal totalitarian regime responsible for sending people to the Gulag).

Re: India bans MasterCard from adding new customers

#170

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

Governments care about financial data for a lot of legitimate reasons, including fraud, criminal activity, etc. Having the data local makes sending legal notices for data access easier and makes supervision easier. A country shouldn't rely on sending international data-access petitions to random data centers with possibly hostile governments who will fight them on jurisdiction and non-treaty grounds. I think what the…

The company does business in India. If they want to continue doing business in India, they will comply with lawful court orders of Indian courts (or whatever other lawful mechanisms exist in India). If they store their data on the Moon, they will have to comply in the exact same way. It changes literally nothing.
Post reply on HN