← Back to context

Comment by KaiserPro

4 hours ago

> start talking about where administrative access and encryption keys lived.

As soon as you start specify technologies, rather than "sovereignty" you end up needing to created specific legal tests to stop people getting around it.

"Data must be stored domestically" is a short hand for being held in the same legal jurisdiction. This means for somewhere like the UK, you get all that battle tested data protections law for free. (new laws require case history to be reliable. Ie, prosecuting under a new law is hard, because if its on the edge of being legal, it can create a precedent that undermines the entire law)

In civil code places, its different, but I don't know enough to offer even a half arsed opinion.

The reason why jurisdiction is important is because if you are storing data outside of your legal protection, when something goes wrong there is little you can do to discourage fuckery.

This is the problem with blinkered engineering thinking. Yes geographically distributed data storage is good. But as you also know, storing it in place with lots of other data, means that its a target. The more places its stored, the more physical security you need. This means that there is higher chance of people being bribed.

Its not a binary, its a multi-dimension graph, with no one answer. Every dimension has a tradeoff.

UAE's tradeoff was: not even trump would ignore all the wargaming that clearly shows kicking iran in the nuts would have inflation rising consequences