Earlier quoted context omitted.
Pretty sure fire is a risk to servers as well.
only in that location. mirror that DB onto a server on the other side of the country, or continent, etc.
Hacker wipes Romania's land registry database
381–390 of 440 posts
Re: Hacker wipes Romania's land registry database
#382Offline and pull based backups FTW... This is why I advocate for a pull or at least push/pull model for backups... where the remote system pulls backups out of your production environment, or otherwise from a drop point. Because a corrupt production system that controls backups can corrupt backups. If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups…
No need to advocate on established best practices. The 3-2-1 rule and its variations are already common place and often mandated by standards/investors and partner contracts.
https://connection-technologies.co.uk/help/backup-disaster-r...
Re: Hacker wipes Romania's land registry database
#383Earlier quoted context omitted.
All those examples are not different from not having backups of digital data too. Making copies when you microfiche, having duplicate stores, it's all exceptionally easy and a solved problem. And of course everything didn't work perfectly, it did however work "perfectly fine", which means "very well" or "good enough". Meanwhile, adding in network connectivity to anything vital these days is just insanely dumb. No sof…
Your overall assessment of advantages and disadvantages seems like you're comparing paper with backups to software without backups, though. No competent system can have all the records destroyed remotely. And we know how to backup digital systems even better than we know how to backup paper ones. And as a third option we can have efficient digital systems that aren't plugged into the Internet. (Presumably the Interne…
I've seen 'competent' backup solutions which had backup rotations that expired older content. And I've read post-incident responses where hackers slowly corrupted older records. And (via reading corporate wikis and docs), determined how long they had to wait, for backups to become tainted.
But I agree. True competent backup methods, including periodic backup restoration tests and other methods, can ensure a degree of protection. Still, one can end up with months of "bad backups" due to a hacker interceding in the process or corrupting records slowly, thus invalidating more recent backup sets post-hack. While this didn't happen with Equifax, the hackers were in there for 8 months slowly exfiling information.
So you can have a load of backups with questionable integrity.
Really, what I'm comparing here is indelible backups vs not. It could be holographic, write only storage for all I care. It's just that "paper" backups, which move to microfiche, have a century long history of how to deal with it. How to ensure they're good. How to keep duplicates, resolve security, and all that.
Meanwhile, most people dealing with the software side simple think "Oh, we can make this situation secure. We can make software secure."
This thought process is entirely wrong. Software is never secure. If you use software + a database or other store for data, it's not secure. And so, placing it online is just plain stupid.
Of course, you speak to other options. No external network connection, for example. And this is all well and good! And it significantly reduces the attack vector.
But of course, and lots of high security environments do this, you then have to ban staff from bringing in all phones, computers, and other devices. I read a post-action report where people's phones were hacked, and basically acted as a 2G modem (at the time) into wifi on an isolated network of a nuclear power plant. And due to the thought process of "We're 100% air gapped, who cares!", the hack was apparently an easy one.
But really, the difference is... how many people can attack your citadel.
The internet means billions. No network connection means hundreds.
It's just that simple. And I think you agree, mostly.
Re: Hacker wipes Romania's land registry database
#384Earlier quoted context omitted.
The Slovak land register was hacked in January 2025. Hackers uknown encrypted the database, asking for an undisclosed 7-figure amount as ransom. The whole country's real estate market was paralyzed for about a month. It took couple of months to restore everything from backups and paper agenda and resume normal operation of the land register office. It was the largest cyber attack in Slovakia's history. The authoritie…
If I remember correctly, this is the hack that Fico tried to blame on Ukraine, even if the hackers were a known Russian ransomware crew that literally posted in their Telegrams about their support for Russia... right?
At this point he is just subverting EU on putin's whims. Stealing half of EU funds evidently wasn't enough for him, plus he can see some protection in the east, west has only future jail for him. If one country should be kicked out right now, it should be this one.
Re: Hacker wipes Romania's land registry database
#385Earlier quoted context omitted.
Don't know exactly on it works in Romania, but proving you purchased a patch of land is a different question -- for that you have the deed. You then submit the deed to the land registry. So this situation could at most result in the seller being able to sell the land more than once or disputes over the priority of sales over liens and other competing acts subject to registration.
The United States is rare. Most countries (seemingly including Romania[1]) have adopted either a cadastral/Torrens title system in which the land registry is definitive legal evidence of who owns a particular piece of land. If you purchased a piece of land and that wasn't recorded in the registry, you are SOL because registration is what conveys title. The United States on the other hand has a massive title insurance…
Sort of. The registration is what provides opposability against third parties. But between buyer and seller, the transfer of ownership happens by the contract itself. You'll have a harder time against creditors of the seller placing liens on the property, or other people claiming to be owners (e.g. if they bought the foreclosed property); how hard a time depends on the country.
And there may be still be encumbrances/claims to the property that are not subjection to registration like adverse possession or rental agreements that can be asserted against the buyer and for which the buyer's only option is to sue to the seller.
Re: Hacker wipes Romania's land registry database
#386Earlier quoted context omitted.
> Apparently tied to Ukraine in this case. Lord no! That accusation doesn't pass the sniff test. Try looking further east for the real culprits.
Ukraine was specifically mentioned in two of the articles I'd referenced, though not in the one originally submitted to HN. I was dubious finding it once, hedged with "apparently" based on the 2nd. I did look for a Wikipedia article on the event which might have included a more substantive and reflective post mortem but didn't find one. If you've specific information clearing or establishing the link, post it. I agre…
That they throw guilt on Ukraine doesn't mean anything at all since its all politics to shift blame anywhere but their own incompetency, especially without specific proofs provided (for which there aren't any even 18 months after the crime).
Re: Hacker wipes Romania's land registry database
#387Earlier quoted context omitted.
https://www.bbc.co.uk/news/articles/ckg15ev0347o
"Under normal circumstances, property law in England and Wales dictates the original owner cannot claim their property back even if the title change was made fraudulently." That's... a curious thing to have in the body of laws. What's its purpose and who does it serve?
The advantages are you can see who owns the land, there's no argument in 20 years time when someone puts a competing claim.
There's an entire industry in the US dedicated to working around the problems that buyers have https://www.alta.org/
If you buy land, then build a house, then someone comes along from 1932 saying "actually that land is mine", you are screwed.
Re: Hacker wipes Romania's land registry database
#388Earlier quoted context omitted.
Capitalists say "you will own nothing" and want a Gini coefficient of 1. Communists don't say "you will own nothing" - they say "abolish private property" and refer to a Gini coefficient of 0.
communists really say "social ownership of the means of production"
I've seen it personally fail miserably and destroy entire nation's spirit for generations to come (on top of other things destroyed for good).
Needless to say, capitalism with its harshness to laziness and carrot on the stick for hard workers got within 2 generations massively ahead, to the point where Gorbachev didn't believe it wasn't Potemkin village setup when visiting some random grocery store in western Germany and seeing the vast amount of produce and quality available to everybody, on level even he personally could only dream of back home.
Re: Hacker wipes Romania's land registry database
#389> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania. So it seems not all has been lost. I was worried about the societal implications of being unable…
This happened in a 50k people town where my father is from in 1982 with a BIG flood that destroyed the town land registry documents (among a lot of the town). Since he's a lawyer, had first hand experience and I was always curious I asked many things about this a while back. Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people. You can never get to 100% recovery like…
Re: Hacker wipes Romania's land registry database
#390Earlier quoted context omitted.
Phone number and email access, if you can regain access to them. It is definitely a good idea to plan in advance and set up a recovery contact: https://support.apple.com/en-us/102641
But email access is protected by MFA based on your destroyed device. Recovery codes are also stored in the same destroyed building.
And that link is to recovery contacts, not codes. If you’re willing to trust one person you can get back into your Apple account after a disaster.