The government official who insisted that commercial AWS/GCP/Azure couldn't possibly be trusted with keeping the information will be keeping their head low for a few days then... "The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for extern…
Agree completely that it's absolute wild to run such a system without backups. But at this point no government should keep critical data on foreign cloud storage.
Fire destroys S. Korean government's cloud storage system, no backups available
311–320 of 987 posts
Re: Fire destroys S. Korean government's cloud storage system, no backups available
#312Earlier quoted context omitted.
ed25519 (and ec25519) are generally understood not to be backdoored by the NSA, or weak in any known sense. The lack of a backdoor can be proven by choosing parameters according to straightforward reasons that do not allow the possibility for the chooser to insert a backdoor. The curve25519 parameters have good reasons why they are chosen. By contrast, Dual_EC_DRBG contains two random-looking numbers, which the NSA p…
> but nobody's been able to break it, either. Absence of evidence is not evidence of absence. It could well be that someone has been able to break it but that they or that organization did not publish.
I agree on the evidence/absence of conjecture. However, the impact of the secret feels impossible to keep.
Time will, of course, tell; it wouldn't be the first occasion where that has embarrassed me.
Re: Fire destroys S. Korean government's cloud storage system, no backups available
#313Earlier quoted context omitted.
[flagged]
How’s that? Using encryption, which is known to have backdoors and is vulnerable to nation state cracking?
Re: Fire destroys S. Korean government's cloud storage system, no backups available
#314Re: Fire destroys S. Korean government's cloud storage system, no backups available
#315Re: Fire destroys S. Korean government's cloud storage system, no backups available
#316I would love to know how a fire of this magnitude could happen in a modern data center.
OVH's massive fire a couple of years ago in one of the most modern DC's at the time was a prime example of just how wrong it can go.
Re: Fire destroys S. Korean government's cloud storage system, no backups available
#317Earlier quoted context omitted.
I'm aware of a big cloud services provider (I won't name any names but it was IBM) that lost a fairly large amount of data. Permanently. So that too isn't a guarantee. They simply should have made local and off-line backups, that's the gold standard, and to ensure that those backups are complete and can be used to restore from scratch to a complete working service.
DigitalOcean lost some of my files in their object storage too: https://status.digitalocean.com/incidents/tmnyhddpkyvf Using a commercial provider is not a guarantee.
Re: Fire destroys S. Korean government's cloud storage system, no backups available
#318Re: Fire destroys S. Korean government's cloud storage system, no backups available
#319https://phrack.org/issues/72/7_md#article
Compromised batteries or battery controllers?
Re: Fire destroys S. Korean government's cloud storage system, no backups available
#320Earlier quoted context omitted.
How does this even make sense business wise for AWS? Is their cost per unit so low?
When you start to do math, hard drive are cheap when you go for capacity and not performance. 0.00099*1000 is 0.99. So about 12$ a year. Now extrapolate something like 5 year period or 10 year period. And you get to 60 to 120$ for TB. Even at 3 to 5x redundancy those numbers start to add up.