Tag: data privacy

  • The New OS Wars

    In the last year I’ve seen a lot of statements about data and sovereignty between countries. While there have been concerns in the past, there seems to be more worry around the world with AI services primarily being run by, and hosted by, US companies. Plenty of my customers at Redgate Software have concerns over our ability to see data when we run AI models, though we don’t store the data. Once the session ends, the data is discarded by policy

    Recently I saw a piece about France trying to rid itself of the reliance on US technology, specifically the Windows OS from Microsoft. They are looking to move to their own version of Linux, as well as a number of open source software packages. This quote was fascinating to me: “We can no longer accept that our data, our infrastructure, and our strategic decisions depend on solutions whose rules, pricing, evolution, and risks we do not control.”

    With AI being added to lots of software, including OSes, I suspect that other countries might look to follow France. I know the EU is looking to move, and Brazil has been trying to use more Linux and OSS for decades. While I find Windows works well, I completely understand wanting to move, especially in this era where many software packages are web-based and can run on a different OS.

    SQL Server runs on Linux, and half of my testing is on Linux, since I run SQL Server in a container on my laptop. My desktop still has a native Windows install, but I find it easy to port almost all code back and forth between the two versions. While I understand others might have a preference for PostgreSQL or MySQL or some other OSS platform, I think SQL Server provides a great value for many organizations. I also think it’s incredibly hard to port your software and data from one database platform to another.

    I do wonder if governments or organizations outside the US that look to leave Windows will also look to leave SQL Server. It’s one thing to move away from the OS and software like Office. A little training will get most users productive on a new system in a relatively short time. Moving a software application and its database is a much larger challenge.

    I expect SQL Server to remain incredibly popular for many years, and with the ability to configure the new AI capabilities to use your own models, I am not sure a country that wants to reduce their reliance on US technology will choose to do so for their databases. They will likely start elsewhere and continue to use SQL Server for years.

    Steve Jones

    Listen to the podcast at Libsyn, Spotify, or iTunes.

    Note, podcasts are only available for a limited time online.

  • The Power of Data and Privacy

    I tend to be fairly careful with data, especially data on this site. When we started the site, we were worried about potential issues and worked hard to ensure we kept our systems safe and limited the attack surface area for personal information. We also declined the various offers we had to sell our list of subscribers to marketing firms. We know that some places add value for marketing, but some abuse the trust of their users and our approach was always to be careful.

    When we sold the site to Redgate, we emphasized the need for this trust, and to date, Redgate has been a great steward of your personal information. I regularly field requests for uses of data from other marketing people, and almost all get declined. I’ve had a number of great managers who have supported me on this because we value your privacy.

    Recently I saw a piece from Troy Hunt, asking who deserves privacy. He runs HaveIBeenPwned, which tracks data breaches. There have been some sensitive breaches, like the Ashley Madison breach, and he has decided to handle some of those differently. I appreciate that, even though I don’t visit any of those sites, I do think there can be unintentional consequences from revealing too much data.

    We certainly have plenty of problems with public data, which was never intended to be accessed at scale. Once someone can query lots of data from one place, they can correlate and use it in ways we never imagined.

    In the piece Troy notes that he has been attacked by some people because he has chosen to redact certain information. This is censorship of a sort, but a) this is a private site, and b) there are good intentions. This service was never intended to be a weapon, and I agree with that. I have rarely censored anyone at SQL Server Central, but it has happened when someone becomes harassing and unprofessional. Our forums are great for civil debate and disagreement, but not for personal attacks.

    I am glad for the restrictions that the GDPR and similar legislation has placed on how companies used data. It has made many individuals and organizations more responsible with how they handle data internally. It hasn’t necessarily helped with data breaches, but at least there are less intentional abuses.

    Data has tremendous power at scale and my view is similar to Troy’s: we all deserve some level of privacy.

    Steve Jones

    Listen to the podcast at Libsyn, Spotify, or iTunes.

    Note, podcasts are only available for a limited time online.

  • Concerns over AI Chat Privacy

    One of the major concerns for using GenAI tools is who is reading the data you submit as a prompt, and will this data be used in future training of the model? In other words, could someone using a future model access the data I put in a GenAI chat?

    It’s a valid concern, and not just because of the vendors. There is a lawsuit over the use of data by OpenAI, and a court has ordered all chats to be retained, including deleted ones. Since this is a lawsuit, there is always a chance that some of the data retained gets entered into a court document or even that it might be read aloud in court and captured in a transcript.

    This is a thorny data privacy issue that collides with the need for courts to maintain evidence for legal proceedings. I honestly don’t know what the answer here is, but I think this should be handled similarly to how code and other IP/proprietary items are handled as evidence. The challenge here is that there can be a lot of evidence, and I am not sure many legal organizations are really set up to handle and manage this much data.

    I’m also not sure who I think should pay for this. If two parties engage in a lawsuit, but the data is actually held in custody by a third party. Do we need to have some nominal charge rate for keeping data that some need to prove their case? Is there a need to force companies like OpenAI and others to hold data in chats for a certain period of time? Something like the 7 or 10 years that a lot of governments require for tax records?

    Our legal systems are outdated and ill-equipped to handle many ways in which the digital world differs from the analogue one. On one hand, I wish that lawmakers would work with advocates and technologists to update laws to make them more relevant, or perhaps, only applicable to digital data.

    On the other, I worry about adding new laws that create overhead, perhaps stifle innovation, or will be out of date as soon as they are passed.

    In 2025, we all should know that anything we send across the internet to another person or service could potentially be disclosed and abused. If that really bothers you, then beware of all free services and be cautious of the paid ones. Read the EULAs and decide if you can accept the risk.

    Because once you send it, your data is out of your control.

    Steve Jones

    Listen to the podcast at Libsyn, Spotify, or iTunes.

    Note, podcasts are only available for a limited time online.

  • Data Sovereignty in the Cloud

    I remember the court case years ago when the US government wanted to access data in Azure that was physically stored in Ireland. I wrote lightly about this and linked to the article back in 2020. This has typically been more of a concern for the EU (and other countries) than the US, but I’m sure there are organizations in the US that use the cloud and don’t want their data accessed by other countries’ governments.

    Recently, a Microsoft executive was asked about this in the French Senate. The Microsoft response was that they  (Microsoft) cannot guarantee data sovereignty for French customers. If the US government served a warrant under the Cloud Act, a US corporation would have to turn over the data.

    While the Internet is fantastic in many ways, especially the ability to communicate and collaborate with others all around the world, we still have physical countries and governments. The rules, regulations, and more vary across different countries, but apparently, those rules aren’t going to be enforced if the company doing business is based in the US.

    This might be good for the US, but not for customers in other countries. In my mind, it’s somewhat amazing that many other countries haven’t had organizations build clouds that work inside their borders. I’m especially surprised the EU hasn’t subsidized or assisted a company in growing as a cloud provider, though likely any organization that grew to a significant size was purchased by Amazon, Google, or Microsoft.

    This access apparently hasn’t happened to date, at least not in a way that is disclosed publicly. Proponents point out that this access would only be allowed with some level of evidence of a crime and a probable cause to access the data in question. That might be true, but we know from the past that a lot of government access to information is kept secret from public disclosure.

    The longer I work with data, the more I find that few organizations truly care about data privacy and protection. They give lip service to the idea, and despite employees sometimes wanting to treat data with care, profit (or other) motivations often override other considerations. I’ve mostly given up on worrying about strong data protections and accepted a significant amount of my data is likely being used by more organizations than I’d like.

    Steve Jones

    Listen to the podcast at Libsyn, Spotify, or iTunes.

    Note, podcasts are only available for a limited time online.