Live data from Hacker News

India bans MasterCard from adding new customers

techcrunch.com

71–80 of 180 posts

Re: India bans MasterCard from adding new customers

#71
post #62
post #6

Earlier quoted context omitted.

The Indian rule seems to require all data be stored strictly inside India, without any of it being stored outside the country. The EU permits data to be transferred outside the EU under a number of circumstances: e.g. if the other country has equivalent data protection laws, if the non-EU company you're transferring the data to has promised to abide by the EU rules, stuff like that. Take this with a grain of salt, of…

Does Indian controlled AJK and Ladakh qualify as "inside India"?

I can't imagine any servers being set up in AJK or Ladakh in the near future.

Re: India bans MasterCard from adding new customers

#72
post #40

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

All data is capable of being decrypted somewhere. Usually where you are storing it. Otherwise you can't do anything with it. Storing data encryped in north korea, with the capability to fetch and decrypt that data in Sweden, is approximately equivalent to storing the unencrypted data in Sweden (as far as hackers, law enforcement, etc. are concerned), except you've now added the additional risk that north korea only n…

Usually where you're processing it, not where you're storing it. That's when you need to do something with it.

Encrypting the data at rest has the major benefit of making its physical location completely irrelevant. Transmitting the data while encrypted has the major benefit of making the physical location of all the nodes through which it passes completely irrelevant. Hence the only thing that matters is the geographic location of where the data is processed, because that is where you decrypt it. All privacy laws should be written with that understanding, but they are not. They are written by people who are ignorant of this simple logic, because they don't understand how Internet works, how encryption works, how routing traffic works and how little it has to do with borders of countries, etc etc.

Healthcare privacy laws in my country, for example, have this exactly 100% backwards. They force me to store data in my country, but say nothing about where it is processed. And of course there's no hard requirement to encrypt data at rest. It's hard to imagine how you can get this kind of law more wrong.

Re: India bans MasterCard from adding new customers

#73
we have known for some time since well before the Tiktok ban in the US, that the world wide web was heading to the fractured web.

It started with china. The moment the world accepted their firewall conditions, it was the moment that we said we are OK with letting you earn the benefits of the web, without the cost of openness.

Open countries could set a marker on this issue. Either you are open or your are not. And if you aren't , you will be dooned to rot in your protectionist web.

We didnt set the marker, so here we are.

Re: India bans MasterCard from adding new customers

#74

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

The obsession with physical data residence comes from the physical nature of government’s power: the ability to apply violence within its borders. The Indian government wants as much data (and encryption keys) inside Indian borders as possible because it can send in guys with guns to take it whenever they want.

Re: India bans MasterCard from adding new customers

#75

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. What do you mean by "properly encrypted"? MasterCard is not going to let you be the sole holder of your encryption keys. And if you aren't holding them, then they they hold it, and then they must be holding in at least one given country. And that country has the power to for…

That country already has the power to force them to turn these keys over (or use the keys to decrypt data of interest). Every non-tax-haven country which regulates its financial sector does (so, every country). It's unclear what is added by forcing them to store data locally.

Re: India bans MasterCard from adding new customers

#76

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

Forcing the data to reside in India. Forces companies to build data centers (jobs) in India. Forces the deployments to be in India. And drives benefits to the local players over international bodies.

Yeah, I suspect that is the logic, such as it is. Quite unburdened with an understanding of how trade works, and seemingly susceptible to the greater fool theory of trade - I'll do it because I'm so smart, but that guy over there won't, and my companies will reap benefits. Not for long.

Re: India bans MasterCard from adding new customers

#77
post #36

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. How about it gets encrypted same way in North Korea or South Korea. Which one would you prefer? What if North Korea says it is properly encrypted and gov has no easy access, but we all know that could be just as well wrong? The U.S. Not exactly enjoys a lot of trust internat…

>How about it gets encrypted same way in North Korea or South Korea. Which one would you prefer?

Whichever is cheaper and/or more reliable. If I trust encryption, all other answers are bogus.

>What if North Korea says it is properly encrypted and gov has no easy access, but we all know that could be just as well wrong?

In this scenario, I decide how to encrypt my data. The storage service is just dumb disk space for me to rent. Call it The People's Democratic B2. Otherwise, it's not really secure no matter who gives you assurances.

Re: India bans MasterCard from adding new customers

#78
post #35

The obsession with where data physically sits at rest is so amusing to me. Not limited to overzealous governments and financial data; healthcare is singularly obsessed with this. It makes no sense whatsoever, of course. I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. I would understand if they demanded both storage and proc…

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country That encryption is pointlesss. North Korea can just demand the key and decrypt your data (assuming the company has presence in that country). Very few services have true end to end encryption. Currently it's not even feasible for healthcare data (homomorphic encryption is not…

North Korea can demand what it wants. I'm not in North Korea.

For North Koreans, all encryption is indeed pointless if the goal is to hide it from the government, regardless of where they want to store data, for this very reason.

I can implement true end-to-end encryption in about 30 minutes (only because I gotta look up where I implemented it last). I will encrypt my data using well known and validated libraries, send it over to the cloud. Retrieve when I need it and decrypt it then. Not sure what about this is not feasible.

Re: India bans MasterCard from adding new customers

#79

Data from Indian transactions should be stored and ideally even processed in India. This seems fair and reasonable to me.

Why does it matter where the data is located?

It matters which jurisdiction can order the data to be decrypted.

Re: India bans MasterCard from adding new customers

#80
There has been alot of innovation in digital payments in India over the last 10 years. There are a number of local alternatives to traditional card brands. This might be a combination of protectionism to support local payment alternatives, and international card network unwillingness to invest in India given declining market share.
Post reply on HN