3 ms·
Being in the EU, I really wonder how this is going to play out if this bill comes to pass. It's pretty clear this bill is incompatible with the GDPR, which spe
by Fradow 6y ago
Being in the EU, I really wonder how this is going to play out if this bill comes to pass.
It's pretty clear this bill is incompatible with the GDPR, which specifically mandates using state of the art encryption when appropriate (and a backdoored encryption is certainly NOT state of the art).
The 2 laws would be fundamentally incompatible, which means we would probably see different services based on geolocation from the big companies (GDPR applies to EU residents, not citizens, so there is no overlap), but this means small players will have to choose between EU and US or take a legal risk.
From a risk perspective, the US have an exception for under 1 million users, while the EU has nothing of the sort. Which means it would, in theory, be less risky to start in the EU, expand in the US, and when you reach the 1 million users bar, separate EU from US operations (which has obviously a lot of issues, how do you handle a user moving from one place to the other, or users interacting accross boundaries?).
Let's hope this won't be the trigger to have several continental/national "internet" instances, but this is definitely going to contribute to a split.
- wizzwizz4 6y agoWe're going to have the "international edition", with 256-bit encryption, and the "US edition" with 40-bit encryption. https://en.wikipedia.org/wiki/40-bit_encryption https://en.wikipedia.org/wiki/40-bit_encryption
- hedora 6y agoThe 1 million user exception doesn’t apply if the government tells you that you need a backdoor. Also, the CLOUD ACT is already incompatible with the GPDR, so cloud vendors are already in a situation where they’re forced to decide which law to break if they receive a warrant.