Hasty Briefsbeta

Bilingual

Kan een Amerikaans bedrijf met encryptie de Amerikaanse overheid buiten de deur houden? - Bert Hubert's writings

a day ago
  • US companies can be compelled by various means to hand over data to the US government, even without judicial review.
  • Encryption alone is insufficient because servers must temporarily access unencrypted data for processing, at which point US law applies.
  • Solutions like Microsoft Double Key Encryption (DKE) are only recommended for highly sensitive data (around 5%) and severely limit functionality.
  • System administrators ultimately have full control over servers, making it impossible to both prevent access and perform necessary management tasks.
  • Practical separation of sensitive data is often too late, as data sensitivity is realized only after the fact.
  • Theoretical solutions like Confidential Computing and Homomorphic Encryption are not yet viable in real-world applications.
  • Claims that using own key management can keep US government out of US-controlled servers are almost always false; renting from a non-US provider is simpler and more effective.