Kan een Amerikaans bedrijf met encryptie de Amerikaanse overheid buiten de deur houden? - Bert Hubert's writings
a day ago
- US companies can be compelled by various means to hand over data to the US government, even without judicial review.
- Encryption alone is insufficient because servers must temporarily access unencrypted data for processing, at which point US law applies.
- Solutions like Microsoft Double Key Encryption (DKE) are only recommended for highly sensitive data (around 5%) and severely limit functionality.
- System administrators ultimately have full control over servers, making it impossible to both prevent access and perform necessary management tasks.
- Practical separation of sensitive data is often too late, as data sensitivity is realized only after the fact.
- Theoretical solutions like Confidential Computing and Homomorphic Encryption are not yet viable in real-world applications.
- Claims that using own key management can keep US government out of US-controlled servers are almost always false; renting from a non-US provider is simpler and more effective.