6 ms·
I'm from Russia, so I guess I could add some context here. A while ago our parliament created a pack of laws to "protect personal data of russian citizens". One
by andreyz4k 10y ago
I'm from Russia, so I guess I could add some context here. A while ago our parliament created a pack of laws to "protect personal data of russian citizens". One of them ordered internet services to store all of the user data of russian citizens on servers, that are physically located in Russia. This law is in power since the beginning of 2016, but many big sites like LinkedIn and Facebook just ignored it. State authorities did nothing about it, but finally, in November they blocked LinkedIn in Russia, so now we ought to use some VPN or proxy to access it. And now they want to remove their apps from stores, despite they don't work without proxy as well.
- akjainaj 10y agoThis is reasonable and, as far as I remember, the EU required the same as well.
- cpncrunch 10y agoNot quite. They just require that you adequately protect PII. Since that is very expensive to do, only large companies tend to do it. Smaller companies probably just ignore it... https://www.wordfence.com/blog/2015/10/european-data-on-usa-servers-safe-harbor/ https://www.wordfence.com/blog/2015/10/european-data-on-usa-...
- qaq 10y agoYou have to account for market size the EU economy is huge Russian economy is about the size of large US city.
- radiorental 10y agoThis is more about sovereignty than GDP
- chatmasta 10y agoHigher GDP allows an economic region to make more demands surrounding their sovereignty.
- disordinary 10y agoAny country is free to make laws around their own sovereignty. Size and power has nothing to do with it. Russia is still a large, connected, and tech savvy country regardless of average income in USD.
- qaq 10y agoNone is disputing that every country can pass whatever laws now having companies care about operating in a given country is very influenced by the GDP and the local laws.
- surfmike 10y agoThe US-EU Safe Harbor Agreement requires that US companies follow the EU's requirements for preserving the privacy and security of users, but allows them to store data in the US.
- cpncrunch 10y agoSafe Harbor doesn't exist any more...
- bjelkeman-again 10y agoReplaced by this. Does anyone know if it is any sgnificantly different? http://europa.eu/rapid/press-release_IP-16-216_en.htm http://europa.eu/rapid/press-release_IP-16-216_en.htm
- kodablah 10y agoI disagree that it is reasonable, but that's why these things are good for at least vote if not left up to consumer choice. I couldn't imagine if my country disabled access to worldwide internet services to protect my data. At some point, citizen choice is valuable, and I as a citizen would like to choose to have my data stored in another country if I wanted (and use services that do so).
- cmdrfred 10y agoI agree in principal but consider this. In real terms this law really only creates and UI/UX problem for LinkedIn at a fundamental level. Sort of like hiding some settings in a config file or behind an "advanced users only!" warning, LinkedIn now requires you connect via a VPN/Tor to use it's services. I feel that the users informed enough to setup a VPN are more likely to also understand the implications of giving personal information to LinkedIn. This has a side effect. If LinkedIn wants to do business with Russia it has to allow access from VPN services. Thus allowing for greater piracy for internet users everywhere.
- douche 10y ago> Thus allowing for greater piracy for internet users everywhere. I assume that's a typo for privacy, but expanding vpn/tor usage probably will help make piracy easier for internet users everywhere
- kodablah 10y agoI really really don't like this sentiment. "In real terms" meaning that you have to intentionally break the law. And only advanced users can get the benefit of worldwide internet services otherwise banned. Granted this is an easy opportunity for a whataboutist, hypocrisy point here concerning other countries, and I'd agree with those countries being incorrect too. We should not be encouraging laws like this, and definitely not excusing them by saying that advanced users can circumvent them. If the Russian government really wanted to protect citizens, why not put laws in place on data protection requirements as opposed to data location requirements? (hint: it's because they don't want to protect the citizens)
- deleted 10y ago[deleted]
- hn_123 10y agoRussian here too. I used to hold similar position on evil west vs. free and for people Russia.... Before I immigrated to the West. I got access to a whole lot more information, I got to live outside of that mentality for a long period of time now. I saw the 90's first hand. My family struggled through it. I was in one of the top schools (a la Russian MIT), making 20$/month.. Barely enough to cover metro cost and not enough for food 3x per day. At the same time as my family was struggling, the president and his oligofriends were stealing and robbing the country. As poor as I was, being at one of the top school allowed me to have friends ... Who had friends - kids of the elite. You see, they tend to send their family abroad, kids go to private British schools. They often have dual citizenships, own real estate and investments in the "evil west". It's a two faced reality, with one face they are critics, with another - they pose for foreign citizenship application. To your comment on the power grab by the "west" and the international elites - yes, it is real IMO. But be careful - watch who is using who to gain that control. The government over there and the judicial systems are not to be trusted. The information grab here is obvious - why give up info on Russian citizens for free to linked in , Google etc.? Of course Russian GRU/FSB etc want to have their hands in it too.
- Mikeb85 10y ago> I saw the 90's first hand. The 90's were courtesy of the west, who sent 'advisers' to Russia to help with the transition to capitalism. Most of the issues the west has with Russia today have to do with the fact we wanted them to stay in the 90's... That was the ideal as far as our leaders are concerned. > I got access to a whole lot more information No, you just got access to a different kind of propaganda. You think families don't struggle here, while the elite take in bribes, engage in cronyism, and send their kids to elite schools? The Clinton's weren't worth hundreds of millions before Bill took office, where did they acquire their wealth? All our corporate 'elite' control our governments, they bribe them (sorry, 'lobby'), and get favourable business deals. The only thing the west has going for it is that people are distracted enough by our relative wealth (enough to buy iPads and shit) to be complacent to all these issues...
- mlvljr 10y ago
- dmoy 10y agoOh is this 242-FZ? If so, that ate up like most of my Q3 2015. My cynical reading of the law was that it was aimed more at having data physically on hand if it needs to be subpoenaed. But IANAL, so maybe I'm just being too cynical. Also what I did or didn't think of the law doesn't matter really, since higher ups decided what was to be done about the law, and I just implemented it.
- dntlkatmyname 10y agoI think that law was just blatant incompetence. For one there is no process for verifying whether or not you actually store anything in Russia. And even then, there's not much of a point in having a physical access to that data unless somebody is stupid enough to store it in plain text.
- TerselyCogent 10y agoThanks for sharing. I believe this is entirely reasonable given the trend of data breaches, which occur everyday. LinkedIn suffered one of the largest breaches, which compromised millions of users. Corporations think that they can disregard the laws of nations and act as independent entities. They use their financial power to influence legislation and steal freedom from individuals. Unbiased regulation is needed to stop expropriation. It's a shame that the article depicted this as censorship. Russia has been under heavy and unjust criticism for quite a while now.
- mgbmtl 10y agoIt wasn't a physical data breach, so I don't think it would make much of a difference. Presumably, it's a way to force Linkedin (and others) to have a subsidiary in Russia (legal entity), which can then be sued if there are problems with regards to Russian law. On one hand, I fully understand your concern. I'm in Canada and the local governments pressure companies such as Netflix, Google and others to have registered legal entities here so that they can apply Canadian law (privacy, tax and language requirements). On the other hand, Russia does not have a good reputation with regards to neutral application of the state of law. Furthermore, Russia does not have good privacy laws. Linkedin probably doesn't have the same resources/expertise as they do in the US. (as a Canadian, I never host my client data in the US for this reason.. it's not that the US is so terrible (although it kind of is w.r.t. privacy/NSA-stuff), but if something happens, we don't have the resources to deal with it)
- csharpminor 10y agoThis has nothing to do with security. If anything, maintaining data centers on a per-country basis would be harder to protect. In-country data requirements add a level of bureaucracy to the web that is just bad for users, as well as companies trying to innovate. This is a combination of both censorship and protectionism.