4 ms·
I think this is due to the data residency requirements in UAE. I'm working with a client in the health space and the government requirements requires me to stor
by rishikeshs 18d ago
I think this is due to the data residency requirements in UAE. I'm working with a client in the health space and the government requirements requires me to store data only in UAE! Tried with AWS but they were not allowing any new instances and I had to go with Azure.
- jackb4040 18d agoHi, I'm from the future. You might want to consider storing the data somewhere besides an Azure datacenter in the UAE.
- r_lee 18d ago> the government requirements requires me to store data only in UAE!
- birdatlaw 18d agoturns out reading comprehension skills have still not gotten better in the future
- jackb4040 18d agoIn the future, some companies begin to store their data on-premises away from big centralized datacenters. But many companies do not, due to costs and the general friction of changing how things are done. If OP tells me the name of his company I can hop in my time machine and tell him how it plays out.
- noeltock 18d agoMENA is the on-prem capital of the world, don't worry.
- instakill 17d agooff-topic but nice username. Fan of Charlie Kelly?
- MisterTea 17d agoThe 'at' in the middle tells me no. I also get Harvey Birdman, Attorney at Law vibes but that could just be me.
- tgsovlerkhgsel 18d ago... but not only in an Azure datacenter! (The obvious option here might be an encrypted backup on some hard drives in a safe in a local office.)
- rishikeshs 17d agoWhat other options I have? I don't like Oracle. GCP has no servers in UAE. All other options were by local providers with not so friendly budget options
- rzzzt 18d agoAre you me from the future? I'm not talking to future strangers. Tell me to deliver the bad news myself from the future, in the future.
- dotancohen 17d agoIt might be the you of Theseus. You really don't want to know what the future holds.
- SecretDreams 18d agoI'm from the past and I concur.
- TeMPOraL 17d agoI'm waiting for a messenger from the future coming back to tell people that passkeys are stupid, and having passwords on post-it notes attached to the monitor was never a real problem, it's just the security industry that got threat modeling backwards for couple decades...
- dormento 17d agoDon't worry. After the great captcha war of 2029 there was an awakening and things got better for a while (until the Flock smart glasses incident...)
- nacnud 17d agoCool! I have a question about lottery numbers..
- deleted 17d ago[deleted]
- nazgulsenpai 17d agoJohn Titor?
- deleted 17d ago[deleted]
- dannyobrien 18d agoHi, I'm from the past. When countries in the 2010s -- especially Western countries -- started seeing data residency requirements as an acceptable aspect of national policies, as opposed to a weird authoritarian thing that only China and Russia imposed on their citizens, we[1] spent a bunch of time explaining to their lawmakers that having geographical redundancy was a good thing, actually, and that you should stop insisting on where the data resided for jurisdictional purposes and start talking about where administrative access and encryption keys lived. [1] OK, "we" here is probably just me -- it was one of those things where the chances of successfully convincing anyone was so small, and the commercial advantages of just nodding along, and then changing your product offering was so great, that really very few people raised it or had reason to. But somebody had to!
- kjs3 18d agoand start talking about where administrative access and encryption keys lived Yeah, that was/is just another problem. Considering how that was actually handled in the real world before data residency laws came into force, I'm glad 'we' didn't convince those countries to put their citizens data at risk.
- dannyobrien 18d agoI'm not sure you were disagreeing with (past) me; but if you were, could you expand on your point?
- kjs3 18d agoI'm disagreeing with you. I in the before time, I had all sorts of conversations around this topic with any number of cloud providers that were like: Us: We are concerned about our citizens (US) data, how are you managing the databases. Clout Provider (CP): They are only managed by fully background check employees. Us: Yeah, but where are they? What is their citizenship? CP: Um...mostly Eastern Europe. Lots in RU. (another CP proudly said "they're pretty much all in China...for cost containment"). Us: ... Us: We are concerned about our citizens (EU) data, how are you managing encryption? CP: Everything is perfectly encrypted with hardware HSMs and all the FIPS and stuff. Us: So...where are the folks who run the HSMs? CP: Um...mostly SV. Some in the EU. Us: But can you assemble a quorum of US citizens for the HSM? CP: Of course! Us: ... And on and on. Not to put too fine a point on it, many of us have no faith that vendors self policing international data protection in the face of government level pressure on companies and employees would work. Not that it can't, I don't think it would.
- jbverschoor 18d agoYou can always selfhost
- alistairSH 18d ago... in the UAE, so only less risky if your office is remote enough it doesn't also make a nice target (like, say, located within/near Dubai's Internet City).
- rishikeshs 17d agoNot an option. Client is non-technical, a one person company
- rudasn 17d agoManaged on-prem perhaps? Setup a server at their office.
- rishikeshs 17d agothis is a remote company, and the person operates from their apartment, so that's not an option!
- tacticus 18d agoCheck if the requirement is "only in the uae" or has to have the primary copy in the UAE
- rishikeshs 17d agoYeah it's a law. Everything health related has to be in UAE.
- johncearls 13d agoI can confirm this. In fact, they require you to physically be in the UAE (no VPN from the states) to access health related data on UAE citizens. Writing this from Abu Dhabi.
- rishikeshs 13d agoHello from AD as well! Glad to know that Hners are here! :)
- rishikeshs 17d agoI rechecked, so for an offshore copy, you need to get special approval from DOH, which in itself is a hassle.
- nullbio 17d agoAzure has outages every 6 hours. It's really pleasant.
- egorfine 17d ago> data residency requirements in UAE Is it a real law? I mean I would largely ignore those kinds of regulations on the basis of sheers stupidity. After all, lawmakers of the world tried to ban math for multiple times in the last few decades. Why would anyone consider conforming to laws like that? Especially since its not possible to enforce this law.
- throwaway173738 17d agoI live in the real world where we follow the law because otherwise some of us might end up in jail and all of us will be out of a job. We pick and choose through our elected officials here.
- rishikeshs 17d agoThe fines are huge and if you don't get things right here and if you're caught, things are quite risky! The fines are also in the range of 100k - 200K USD
- egorfine 15d agoLet's say I have a tiny box somewhere that's only job is to periodically do something like this: ssh local-server "rsync /data foreignserver:/backup" How could this be discovered? How come this kind of solutions are now in the legal territory?
- rishikeshs 15d agoI know right. It won't be discovered, but it's about doing what's right. For some reason if something goes wrong and there's an audit, the company is screwed. Ref to law: https://uaelegislation.gov.ae/en/legislations/1209/download https://uaelegislation.gov.ae/en/legislations/1209/download
- egorfine 15d agoSo the solution is to not incorporate in hostile jurisdictions. The problem is that the circle of human-friendly jurisdictions is shrinking.