- state level actors can basically break into any computer system given enough time
- corporate databases have a gigantic amount of information on everyon
- states want all of that data
I hope the conclusion is as straightforward as it seems to me.
OK, not exactly what you are responding about Let's talk about corporate IT systems, let's get into "deleted". Is it:
- deleted from backups? Almost universally this answer will be no.
- deleted from each and every database and system in your presumably huge corporation, which may involve literally thousands of IT systems? I'd guess no.
- is it deleted by moving the data to a separate "deleted data" table or database, thus sequestering the data from the "active data" rather than deleting it, just in case you want to "undo"?
- is it deleted from all system logs?
- is it deleted from all records systems that may have minimum retention periods legally or by policy?
- what about data warehouses or data lakes that repackage/mirror data?
I'd accuse you too. If you can't read their data, then the data doesn't exist? Also, if you can't read read their data, how are the customers seeing it on their dashboard?
In the automotive space we are leaning heavily on confidential computing primitives to make it actually impossible, for example keys generated entirely inside enclaves and only attested software can run on those etc etc.
And of course we did that not because we are nice people (though we belive we are). We did it, because we had the hypothesis that a reputation to handle the user-data with proofable utmost respect to security and privacy would be more valuable than having access to this data.
People not believing us or accusing us of lying obviously defy that hypothesis.