Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

221–230 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#221
post #127

Earlier quoted context omitted.

Why not? If the region is in country, encrypted, and with proven security attestations validated by third parties, a backup to a cloud storage would be incredibly wise. Otherwise we might end up reading an article about a fire burning down a single data center

Exactly. Like, don't store it in the cloud of an enemy country of course. But if it's encrypted and you're keeping a live backup in a second country with a second company, ideally with a different geopolitical alignment, I don't see the problem.

A country can become an adversary faster than a government can migrate away from it.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#222

Earlier quoted context omitted.

I agree. No automated fire suppression system for critical infrastructure with no backup?

That may not be a perfect answer. One issue with fire suppression systems and spinning rust drives is that the pressure change etc. from the system can also ‘suppress’ the glass platters in drives as well.

That's why the top-security DCs that my employer operates have large quantities of Nitrogen stored, and use that slightly lower the O2 saturation of the air in the case of fire.

Yes, it's fucking expensive, that's one of the reason you pay more for a VM (or colocation) than at Hetzner or OVH. But I'm also pretty confident that single fire wouldn't destroy all hard drives in that IT space.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#223
post #98

Earlier quoted context omitted.

Rightfully did not trust these companies. Sure what happened is a disaster for them, but you cant simply trust Amazon & Microsoft.

Why not? You can easily encrypt your data before sending it for storage on on S3, for example.

Is encryption, almost any form, really reliable protection for a countries' government entire data? I mean, this is _the_ ultimate playground for "state level actors" -- if someday there's a hole and it turns out it takes only 20 years to decrypt the data with a country-sized supercomputer, you can bet _this_ is what multiple alien countries will try to decrypt first.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#225
post #169

Earlier quoted context omitted.

I agree. No automated fire suppression system for critical infrastructure with no backup?

Battery fire is impossible to suppress.

That's why in high-quality DCs, battery backup is in a separate room with good fire isolation from the IT space.

Yes, the servers still have some small batteries on their mainboards etc, but it's not too bad.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#226
post #186
post #127

Earlier quoted context omitted.

Why not? If the region is in country, encrypted, and with proven security attestations validated by third parties, a backup to a cloud storage would be incredibly wise. Otherwise we might end up reading an article about a fire burning down a single data center

Microsoft has already testified that the American government maintains access to their data centres, in all regions. It likely applies to all American cloud companies. America is not a stable ally, and has a history of spying on friends. So unless the whole of your backup is encrypted offline, and you trust the NSA to never break the encryption you chose, its a national security risk.

> America is not a stable ally, and has a history of spying on friends

America is a shitty ally for many reasons. But spying on allies isn’t one of them. Allies spy on allies to verify they’re still allies. This has been done throughout history and is basic competency in statecraft.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#228

The government official who insisted that commercial AWS/GCP/Azure couldn't possibly be trusted with keeping the information will be keeping their head low for a few days then... "The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for extern…

He may or may not have been right, but it's besides the point.

The 3-2-1 backup rule is basic.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#229
post #120

The government official who insisted that commercial AWS/GCP/Azure couldn't possibly be trusted with keeping the information will be keeping their head low for a few days then... "The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for extern…

Agree completely that it's absolute wild to run such a system without backups. But at this point no government should keep critical data on foreign cloud storage.

> no government should keep critical data on foreign cloud storage

Primary? No. Back-up?

These guys couldn’t provision a back-up for their on-site data. Why do you think it was competently encrypted?

Post reply on HN