4 ms·
The FBI can request until they’re blue in the face. They don’t make laws. And so far, there aren’t any laws preventing Apple from encrypting backups.
by barsonme 5y ago
The FBI can request until they’re blue in the face. They don’t make laws. And so far, there aren’t any laws preventing Apple from encrypting backups.
- robertwt7 5y agoRight.. yeah because some laws like anti terrorism or money laundering etc stated that tech companies has to save the data and share with the gov if the gov requested. Source: I work in fintech
- Hamuko 5y agoDo these laws specify that you're not allowed to make features that encrypt data?
- robertwt7 5y agoNo not that, what I meant was that you have to be able to provide when requested. Meaning that you have to be able to decrypt it if requested. Not just 1 way encryption
- Hamuko 5y agoSo is Amazon breaking the law if I upload GPG-encrypted files to S3?
- rswail 5y agoNo, because AWS is not providing financial services. If you are and you upload encrypted data to S3, then you'd better have the ability to decrypt it if required by the financial regulators, otherwise you are breaking the law.
- Hamuko 5y agoThis sounds a lot more like financial institution regulation than tech company regulation.
- robertwt7 5y agoYes but the point is the government has the ability to do that. Exactly my question
- pseudalopex 5y agoYou said "tech companies has to save the data and share with the gov".
- leeoniya 5y agoas long as you also make features to decrypt same data
- rswail 5y agoIf you work in finance and are subject to AML/KYC (anti money laundering, know your customer) laws, then it's not whether or not you encrypt data. You cannot encrypt the data in a way that is not accessible under those laws for the transactions you perform. So that has nothing to do with the mechanism of securing data and everything to do with the finance organization compliance with the laws. "Fintech" is a fancy word for a company doing financial applications, not a copout on financial regulations by using the "tech" word as an excuse. There are a bunch of standards requiring encryption at rest and encryption in transit of PII and other data in finance. That does not mean that authorized users do not have access to it.