Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

The key issue, I think, is not what law-theoretically does and does not theoretically oblige you to comply with a jurisdiction, but the assets and people which are within reaching distance of the applicable government. Whether a service is accessible from the UK is irrelevant so long as you have no assets, no employees in the UK. Conversely, if you have assets or employees in the UK, you can expect them to be under threat of seizure or coercion, respectively.

I also don't think it's a safe assumption in any jurisdiction nowadays that the person who gets served with a notice will be an executive. It seems quite plausible to me that a front-line engineer could get served with a notice, and not even be allowed to tell an executive. Thus, even if your employees in the UK don't appear to have been coerced, this appearance could be deceiving.

There may be some limited countermeasures to this sort of thing, like regular audits of system configurations, etc. performed by a different group of people, and who will thus cry murder if they find any anomalies. This should work because the second group of people will not be the target of a notice, and thus not bound by its secrecy provisions. Possibly this group could do their auditing remotely, from outside the UK. Of course the in-UK group could, under coercion, rootkit the system to hide these changes, probably by being told to install government-issued software. Hmm...



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: