Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

371–380 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#371

Earlier quoted context omitted.

You can use and abuse encrypted one time pads and multiple countries to guarantee it’s not retrievable.

You're assuming a level of competency that's hard to warrant at this point.

If your threat model is this high that you assume encryption breaking to be into your threat model, then maybe you do need a level of comeptency in the process as well.

They have 2 Trillion $ economy. I am sure that competency shouldn't be the thing that they should be worrying at that scale but at the same time I know those 2 trillion $ don't really make them more competent but I just want to share that it was very possible for them to teach/learn the competency

Maybe this incident teaches us atleast something. Definitely something to learn here though. I am interested in how the parent comment suggests sharing one time pad or rather a practical way for them to do so I suppose since I am genuinely curious as most others refer to using the cloud like aws etc. and I am not sure how much they can share something like one time pad and at the scale of petabytes and more, I can maybe understand it but I would love if the GP can tell me a practical way of doing so to atleast have more safety I suppose than encryption methods I suppose..

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#372
At the very bottom of the article, I see this notice:

    > This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom.
I like that. It is direct and honest. I'm fine with people using LLMs for natural language related work, as long as they are transparent about it.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#375

Earlier quoted context omitted.

Am I missing something? If you ever need to use this data, obviously you transfer it back to your premises and then decrypt it. Whether it's stored at Amazon or North Korean Government Cloud makes no difference whatsoever if you encrypt before and decrypt after transfer.

They can take the data hostage, the foreign nation would have no recourse.

Have it in multiple countries with multiple providers if money isn't a concern.

And are we forgetting that they can literally have a multi cloud backup setup in their own country as well or incentivize companies to build their datacenters there in partnership with them of sorts with a multi cloud setup as I said earlier?

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#376
post #324
post #224

Earlier quoted context omitted.

Silver lining: it's likely that technically there is a backup (section 1.3). It's just in NK or china. Yikes.

I don't backup my phone. The NSA does it for me!

The recovery process and customer service around that is near impossible

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#378

The government official who insisted that commercial AWS/GCP/Azure couldn't possibly be trusted with keeping the information will be keeping their head low for a few days then... "The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for extern…

The simple solution here would have been something like a bunch of netapps with snapmirrors to a secondary backup site.

Or ZFS or DRBD or whatever homegrown or equivalent non-proprietart alternative is available these days and you prefer.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#379
post #175

Earlier quoted context omitted.

S3 features have saved our bacon a number of times. Perhaps your experience and usage is different. They are worth trusting with business critical data as long as you're following their guidance. GCP though have not proven it, their data loss news is still fresh in my mind.

Were you talking about this incidence? https://arstechnica.com/gadgets/2024/05/google-cloud-acciden... I am currently evaluating between GCP and AWS right now.

I read the article and it seems that, that thing happened because their account got deleted and here is something from the article you linked

Google Cloud is supposed to have safeguards that don't allow account deletion, but none of them worked apparently, and the only option was a restore from a separate cloud provider (shoutout to the hero at UniSuper who chose a multi-cloud solution).

If you are working with really important software, please follow the 3-2-1 EVEN with cloud providers I suppose if you genuinely want ABSOLUTE guarantee I suppose, but it depends on how important the data is I suppose for the prices.

I have thought about using some cheap like backblaze and wasabi and others for the 3-2-1 for backups I suppose I am not sure but I do think that this incident was definitely a bit interesting to read into and I will read more about it, I do remember it from kevin fang's video but this article is seriously good and I will read it later, bookmarked.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#380
post #325

Earlier quoted context omitted.

You're assuming that this needs to protect... > ... a countries' government entire data? But the bulk of the data is "boring": important to individuals, but not state security ("sorry Jiyeong, the computer doesn't know if you are a government employee. Apologies if you have rent to make this month!") There likely exists data where the risk calculation ends up differently, so that you wouldn't store it in this system.…

A foreign gov getting all your security researchers and staff's personal info with their family and tax and medical records doesn't sound great. That's just from the top of my head. Exploiting such a trove of data doesn't sound complicated.

Yeah that ignores about two thirds of my point, including that it would never get to the "Exploiting such a trove of data doesn't sound complicated" stage with a higher probability than storing it within one's own territory
Post reply on HN