‹ BackHN Continuity

Thread

AWS says it can't restore some data from mideast facilities struck by Iran

530 points · 452 comments · berkeleyjunk

  1. rishikeshs · · focus · HN ↗
    I think this is due to the data residency requirements in UAE. I'm working with a client in the health space and the government requirements requires me to store data only in UAE! Tried with AWS but they were not allowing any new instances and I had to go with Azure.
    1. dannyobrien · · focus · HN ↗
      Hi, I'm from the past. When countries in the 2010s -- especially Western countries -- started seeing data residency requirements as an acceptable aspect of national policies, as opposed to a weird authoritarian thing that only China and Russia imposed on their citizens, we[1] spent a bunch of time explaining to their lawmakers that having geographical redundancy was a good thing, actually, and that you should stop insisting on where the data resided for jurisdictional purposes and start talking about where administrative access and encryption keys lived.

      [1] OK, "we" here is probably just me -- it was one of those things where the chances of successfully convincing anyone was so small, and the commercial advantages of just nodding along, and then changing your product offering was so great, that really very few people raised it or had reason to. But somebody had to!

      1. KaiserPro · · focus · HN ↗
        > start talking about where administrative access and encryption keys lived.

        As soon as you start specify technologies, rather than "sovereignty" you end up needing to created specific legal tests to stop people getting around it.

        "Data must be stored domestically" is a short hand for being held in the same legal jurisdiction. This means for somewhere like the UK, you get all that battle tested data protections law for free. (new laws require case history to be reliable. Ie, prosecuting under a new law is hard, because if its on the edge of being legal, it can create a precedent that undermines the entire law)

        In civil code places, its different, but I don't know enough to offer even a half arsed opinion.

        The reason why jurisdiction is important is because if you are storing data outside of your legal protection, when something goes wrong there is little you can do to discourage fuckery.

        This is the problem with blinkered engineering thinking. Yes geographically distributed data storage is good. But as you also know, storing it in place with lots of other data, means that its a target. The more places its stored, the more physical security you need. This means that there is higher chance of people being bribed.

        Its not a binary, its a multi-dimension graph, with no one answer. Every dimension has a tradeoff.

        UAE's tradeoff was: not even trump would ignore all the wargaming that clearly shows kicking iran in the nuts would have inflation rising consequences

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.