Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

241–250 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#241
post #122
post #80

https://phrack.org/issues/72/7_md#article

Woah, read the timeline at the top of this. The fire happened the very day the government ordered onsite inspection was supposed to start due to Chinese/NK hacking.

So, someone figured out how to do backups

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#242
post #159
post #120

Earlier quoted context omitted.

Agree completely that it's absolute wild to run such a system without backups. But at this point no government should keep critical data on foreign cloud storage.

Encrypted backups would have saved a lot of pain here

Any backup would do at this point. I think the most best is: encrypted, off-site & tested monthly.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#243
post #186
post #127

Earlier quoted context omitted.

Why not? If the region is in country, encrypted, and with proven security attestations validated by third parties, a backup to a cloud storage would be incredibly wise. Otherwise we might end up reading an article about a fire burning down a single data center

Microsoft has already testified that the American government maintains access to their data centres, in all regions. It likely applies to all American cloud companies. America is not a stable ally, and has a history of spying on friends. So unless the whole of your backup is encrypted offline, and you trust the NSA to never break the encryption you chose, its a national security risk.

> France spies on the US just as the US spies on France, the former head of France’s counter-espionage and counter-terrorism agency said Friday, commenting on reports that the US National Security Agency (NSA) recorded millions of French telephone calls.

> Bernard Squarcini, head of the Direction Centrale du Renseignement Intérieur (DCRI) intelligence service until last year, told French daily Le Figaro he was “astonished” when Prime Minister Jean-Marc Ayrault said he was "deeply shocked" by the claims.

> “I am amazed by such disconcerting naiveté,” he said in the interview. “You’d almost think our politicians don’t bother to read the reports they get from the intelligence services.”

> “The French intelligence services know full well that all countries, whether or not they are allies in the fight against terrorism, spy on each other all the time,” he said.

> “The Americans spy on French commercial and industrial interests, and we do the same to them because it’s in the national interest to protect our companies.”

> “There was nothing of any real surprise in this report,” he added. “No one is fooled.”

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#244

Meanwhile, Estonia has a "data embassy" in Luxembourg: https://e-estonia.com/solutions/e-governance/data-embassy/ TL;DR: Estonia operates a Tier 4 (highest security) data center in Luxembourg with diplomatic immunity. Can actively run critical government services in real-time, not just backups.

> Estonia follows the “once-only” principle: citizens provide their data just once, and government agencies re-use it securely. The next step is proactive services—where the government initiates service delivery based on existing data, without waiting for a citizen’s request.

I wish the same concept was in Canada as well. You absolutely have to resubmit all your information every time you do a request. On top of that, federal government agencies still mail each other the information, so what usually can be done in 1 day takes a whole month to process, assuming the mail post isn't on strike (spoiler: they are now).

I think Canada is one of the worst countries in efficiency and useless bureaucracy among 1st world countries.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#245
post #209
post #186

Earlier quoted context omitted.

Microsoft has already testified that the American government maintains access to their data centres, in all regions. It likely applies to all American cloud companies. America is not a stable ally, and has a history of spying on friends. So unless the whole of your backup is encrypted offline, and you trust the NSA to never break the encryption you chose, its a national security risk.

Not only does the NSA break encryption but they actually sabotage algorithms to make them easier to break when used.

Can the NSA break the Ed25519 stuff? Like the crypto_box from libsodium?

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#246
post #186

Earlier quoted context omitted.

Microsoft has already testified that the American government maintains access to their data centres, in all regions. It likely applies to all American cloud companies. America is not a stable ally, and has a history of spying on friends. So unless the whole of your backup is encrypted offline, and you trust the NSA to never break the encryption you chose, its a national security risk.

> America is not a stable ally, and has a history of spying on friends America is a shitty ally for many reasons. But spying on allies isn’t one of them. Allies spy on allies to verify they’re still allies. This has been done throughout history and is basic competency in statecraft.

That doesn’t capture the full truth. Since Snowden, we have hard evidence the NSA has been snooping on foreign governments and citizens alike with the purpose of harvesting data and gathering intelligence, not just to verify their loyalty.

No nation should trust the USA, especially not with their state secrets, if they can help it. Not that other countries are inherently more trustworthy, but the US is a known bad actor.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#247
post #89

It's hard to believe this happened. South Korea has tech giants like Samsung, and yet this is how the government runs? Is the US government any better?

Software and information technology in Korea just sucks. buttons are jpegs/gifs, everything is on Java EE and on vulnerable old webservers etc... A lot of government stuff supports only Internet Explorer even though it's long dead

Remember Log4j vulnerability? A lot of the Korea governmental sites weren't affected because the Java version was too old :)

Don't even get me started on ActiveX.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#249
post #155

Earlier quoted context omitted.

The first thing that comes to mind when I think of the South Korean government is the storied tradition of physical confrontation in their parliament along with more than a few viral videos of brawls and such over the years. It used to be better in the US, but with the intensity of discord in our government lately, I don't think anyone really knows anymore.

> The first thing that comes to mind when I think of the South Korean government is the storied tradition of physical confrontation in their parliament along with more than a few viral videos of brawls and such over the years You're thinking of Taiwan, not South Korea.

No South Korea has the same thing. It doesn't happen yearly but has happened quite a bit. We lovingly call it parliament siege raid.

https://m.blog.naver.com/gard7251/221339784832 (a random blog with gifs)

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#250
post #205

Earlier quoted context omitted.

Exactly. Like, don't store it in the cloud of an enemy country of course. But if it's encrypted and you're keeping a live backup in a second country with a second company, ideally with a different geopolitical alignment, I don't see the problem.

From the perspective of securing your data, what's the practical difference between a second country and an enemy country? None. Even if it's encrypted data, all encryption can be broken, and so we must assume it will be broken. Sensitive data shouldn't touch outside systems, period, no matter what encryption.

> From the perspective of securing your data, what's the practical difference between a second country and an enemy country? None.

Huh? An enemy country will shut off your access. Friendly countries don't.

> Even if it's encrypted data, all encryption can be broken, and so we must assume it will be broken.

This is a very, very hot take.

Post reply on HN