4 ms·
I'm curious if this has anything to do with the Tech Support scams that seem to be commonly based in India. Microsoft would have an interest in helping law enfo
by gfo 8y ago
I'm curious if this has anything to do with the Tech Support scams that seem to be commonly based in India. Microsoft would have an interest in helping law enforcement fight those schemes as many purport to be from "Microsoft Support".
Also of note, the Bank of India said they received no requests in 2016 or 2017 from Microsoft but the first paragraph notes the ~4000 requests were made from 2014-2016.
- squaresmile 8y agoI think they are two different things: > The RBI said Microsoft agreed to disclose information on 3,036 occasions between 2014 and 2016 in response to more than 4,000 government requests or legal demand requests for data of Indian customers in the US. > according to Microsoft, it had received “zero demands from the US law enforcement for commercial enterprise content located outside the United States” in 2016 and 2017. In the first sentence, I think the requests were from the RBI and not US intelligence.
- antsar 8y agoInteresting that the second quote says "content located outside the United States", not "content pertaining to customers located outside the united states". They can just keep a copy in both places, allowing them to simultaneously "have zero requests for content outside the US" and "share data of India bank customers".
- pacohope 8y agoIf you believe that cloud providers just copy your data willy-nilly from place to place, you've obviously never dealt with the cloud before. They go to great pains to earn trust by making sure that your data only lives where you put it. You haven't read any of their documentation, you haven't looked into the independent, third-party audits that verify that their documentation is true. You know what region you put your data in, and the cloud provider doesn't surrepititiously copy places without your knowledge. If your approach to risk management is that cloud providers will do the opposite of what they write in documentation and that the third party auditors are lying or not actually seeing what really happens, you'll never be able to use any equipment that you don't personally manage. You'd never be able to use a managed data centre or a so-called "private cloud" either, because all these providers could just tell you one thing and do another. Then there's the simple fact that it doesn't scale to copy everybody's data to the US. When you're as big as one of these major cloud providers, that's just simply not possible.