Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

321–330 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#321
A lot of folks are arguing that the real problem is that they refused to use US cloud providers. No, that's not the issue. It's a perfectly reasonable choice to build your own storage infrastructure if it is needed.

But the problem is they sacrificed "Availability" in pursuit of security and privacy. Losing your data to natural and man-made disasters is one of the biggest risks facing any storage infrastructure. Any system that cannot protect your data against those should never be deployed.

"The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for external backups."

This is not a surprise to them. They had knowingly accepted the risk of infrastructure being destroyed by natural and man-made disasters. I mean, WTF!

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#322
post #312

Earlier quoted context omitted.

> but nobody's been able to break it, either. Absence of evidence is not evidence of absence. It could well be that someone has been able to break it but that they or that organization did not publish.

How could you not!? Think of the bragging rights. Or, perhaps the havoc. That persons could sit on this secret for long periods of time seem... difficult to maintain. If you know it's broken and you've discovered it; surely someone else could too. And they've also kept the secret? I agree on the evidence/absence of conjecture. However, the impact of the secret feels impossible to keep. Time will, of course, tell; it…

There are a large number mathematicians gainfully employed in breaking such things without talking about it.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#324
post #224
post #80

https://phrack.org/issues/72/7_md#article

Silver lining: it's likely that technically there is a backup (section 1.3). It's just in NK or china. Yikes.

I don't backup my phone. The NSA does it for me!

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#325

Earlier quoted context omitted.

Why not? You can easily encrypt your data before sending it for storage on on S3, for example.

Is encryption, almost any form, really reliable protection for a countries' government entire data? I mean, this is _the_ ultimate playground for "state level actors" -- if someday there's a hole and it turns out it takes only 20 years to decrypt the data with a country-sized supercomputer, you can bet _this_ is what multiple alien countries will try to decrypt first.

You're assuming that this needs to protect...

> ... a countries' government entire data?

But the bulk of the data is "boring": important to individuals, but not state security ("sorry Jiyeong, the computer doesn't know if you are a government employee. Apologies if you have rent to make this month!")

There likely exists data where the risk calculation ends up differently, so that you wouldn't store it in this system. For example, for nuke launch codes, they might rather lose than loose them. Better to risk having to reset and re-arm them than to have them hijacked

> Is encryption, [in?] any form, really reliable protection

There's always residual risk. E.g.: can you guarantee that every set of guards that you have watching national datacenters is immune from being bribed?

Copying data around on your own territory thus also carries risks, but you cannot get around it if you want backups for (parts of) the data

People in this thread are discussing specific cryptographic primitives that they think are trustworthy, which I think goes a bit deeper than makes sense here. Readily evident is that there are ciphers trusted by different governments around the world for their communication and storage, and that you can layer them such that all need to be broken before arriving at the plain, original data. There is also evidence in the Snowden archives that (iirc) e.g. PGP could not be broken by the NSA at the time. Several ciphers held up for the last 25+ years and are not expected to be broken by quantum computers either. All of these sources can be drawn upon to arrive at a solid choice for an encryption scheme

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#326
post #184
post #163

Earlier quoted context omitted.

And which organization has every file, from each of their applications using the cloud, encrypted *before* it is sent to the cloud?

They're talking about backups. you can absolutely send an updated copy every night.

True, the user I was replying to only mentioned backups.

For those there's sure no problem

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#327

I must say, at least for me personally when I hear about such levels of incompetence it rings alarm bells in my head making me think that maybe intentional malice was involved. Like someone higher up had set up the whole thing to happen in such a matter because there was a benefit to this happening we are unaware of. I think this belief maybe stems from lack of imagination on how really stupid humans can get.

Most people overestimate the prevalence of malice, und underestimate the prevalence of incompetence

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#328
post #191

Earlier quoted context omitted.

>As a government you should not be putting your stuff in an environment under control of some other nation, period. Why? If you encrypt it yourself before transfer, the only possible control some_other_nation will have over you or your data is availability.

You're forgetting that you're talking nation states, here. Breaking encryption is in fact the role of the people you are giving access. Sovereign delivery makes sense for _nations_.

You can use and abuse encrypted one time pads and multiple countries to guarantee it’s not retrievable.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#329
post #310

Earlier quoted context omitted.

[flagged]

How’s that? Using encryption, which is known to have backdoors and is vulnerable to nation state cracking?

>Using encryption, which is known to have backdoors and is vulnerable to nation state cracking?

WTF are you talking about? There are absolutely zero backdoors of any kind known to be in any standard open source encryption systems, and symmetric cryptography 256-bits or more is not subject to cracking by anyone or anything, not even if general purpose quantum computers are doable and prove scalable. Shor's algorithm applies to public-key not symmetric, where the best that can be done is Grover's quantum search for a square-root speed up. You seem to be crossing a number of streams here in your information.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#330

Earlier quoted context omitted.

“The BBC understands that customers, through various backup technologies, external, were able to recover all lost data.” You backup stuff. To other regions.

But the Korean government didn't backup, that's the problem in the first place here…

Sure. Using a cloud can make that more convenient. But obviously not so if you then keep all your data in the same region, or even “availability-zone” (which seems to be the case for the all “lost to lightening strikes” data here).
Post reply on HN