Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

561–570 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#561

What structure could possibly preclude backups? I've never seen anything that couldn't be copied elsewhere. Maybe it was just convenient to have the possibility of losing everything.

Its Korea, so most likely fear of annoying higher up when seeking approvals.

Koreans are weird, for example they will rather eat contractual penalty than report problems to the boss.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#563

Earlier quoted context omitted.

I spent a week of my life at a major insurance company in Seoul once, and the military style security, the obsession with corporate espionage, when all they were working on was an internal corporate portal for an insurance company… The developers had to use machines with no Internet access, I wasn’t allowed to bring my laptop with me lest I use it to steal their precious code. A South Korean colleague told me it was…

> South Korean corporate management is stuffed full of ex-military officers For those unaware, all "able-bodied" South Korean men are required to do about two years of military service. This sentence doesn't do much for me. Also, please remember that Germany also had required military service until quite recently. That means anyone "old" (over 40) and doing corp mgmt was probably also a military officer.

Depends on if these were commissioned officers or NCOs. Basically everyone reaches NCO by the end of service (used to be automatic, now there are tests that are primarily based around fitness), but when people specifically call out officers they tend to be talking about ones with a commission. You are not becoming a commissioned officer through compulsory service.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#564

wow https://x.com/koryodynasty/status/1973956091638890499 > A senior government official overseeing recovery efforts for South Korea's national network crisis has reportedly died by suicide in Sejong.

If the US government and corporate executives had even half this level of shame, we'd have nobody left in those positions!

Not the same country but another example of a culturally similar attitude towards shame over failure: In Japan in 1985, Flight 123, a massive Boeing 747 carrying 524 people, lost control shortly after takeoff from Tokyo en route to Osaka.

The plane's aft pressure bulkhead catastrophically exploded, causing total decompression at the high altitude, severing all four of the massive plane's hydraulic stabilizer systems and entirely tearing away its vertical stabilizer.

With these the 747 basically became uncontrollable and minutes later, despite tremendously heroic efforts by the pilots to turn back and crash land it with some modicum of survivability for themselves and the passengers, the flight slammed into a mountain close to Tokyo, killing hundreds.

The resulting investigation showed that the failed bulkhead had burst open due to faulty repair welding several years before. The two technicians most responsible for clearing that particular shoddy repair both committed suicide soon after the crash tragedy. One of them even left a note specifically stating "With my death I atone". (paraphrasing from memory here)

I can't even begin to imagine a modern Boeing executive or senior staffer doing the same.

Same couldn't be said for Japanese military officials after the tragedy though, so who knows about cultural tendencies:

Right after the crash, helicopters were making ready to fly to the scene (it was night by this point) and a nearby U.S military helicopter squadron also even offered to fly in immediately. The local JSDF administration however stood all these requests down until the following morning, on the claim that such a tremendous crash must not have left anyone alive, so why hurry?

As it turned out, quite a number of people had incredibly survived, and slowly died during the night from exposure to cold and their wounds, according to testimony from the four who did survive to be rescued, and doctors who later conducted postmortems on the bodies.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#566
Is it just me, or is this a massively better result than "1PB of government documents containing sensitive data about private individuals was exfiltrated to a hacker group and found for sale"?

I applaud them for honouring their obligation to keep such data private. And encourage them to work on their backup procedures while continuing to honour that obligation.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#567
post #491

Goodness, I have over 100TB at home and it cost less than a two or three thousand dollars to put in place. That's like $25 per TB. > The stored data amounts to 858TB (terabytes), equivalent to 449.5 billion A4 sheets. No, the 858TB amounts to under $25k for the government of the 10th largest economy, of one of the most sophisticated countries on the planet, to put in place. Two of those would be less than the price o…

You can buy a 24Tb drive on sale for $240 or so. Sometimes I wonder why I still try and save disk space :-/

Link? Am both curious and skeptical

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#568

Earlier quoted context omitted.

Samsung owns Joyent

Nevertheless isn't Joyent registered in the US?

The last time I heard of Joyent was in the mid-2000s on John Gruber’s blog when it was something like a husband-and-wife operation and something to do with WordPress or MovableType - 20 years later now it’s a division of Samsung?

My head hurts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#569

Meanwhile, Estonia has a "data embassy" in Luxembourg: https://e-estonia.com/solutions/e-governance/data-embassy/ TL;DR: Estonia operates a Tier 4 (highest security) data center in Luxembourg with diplomatic immunity. Can actively run critical government services in real-time, not just backups.

> Estonia follows the “once-only” principle: citizens provide their data just once, and government agencies re-use it securely. The next step is proactive services—where the government initiates service delivery based on existing data, without waiting for a citizen’s request. I wish the same concept was in Canada as well. You absolutely have to resubmit all your information every time you do a request. On top of that…

I wanted to update some paperwork to add my wife as a beneficiary to some accounts. I go to the bank in person and they tell me “call this number, they can add the beneficiary”. I call the number and wait on hold for 30 minutes and then the agent tells me that they will send me an email to update the beneficiary. I get an email over 24 hours later with a PDF THAT I HAVE TO PRINT OUT AND SIGN and then scan and send back to the email. I do that, but then I get another email back saying that there is another form I have to print and sign.

This is the state of banking in Canada. God forbid they just put a text box on the banking web app where I can put in my beneficiary.

Not to mention our entire health care system still runs on fax!

It blows my mind that we have some of the smartest and well educated people in the world with some of the highest gdp per capita in the world and we cannot figure out how to get rid of paper documents. You should be issued a federal digital ID at birth which is attested through a chain of trust back to the federal government. Everything related to the government should be tied back to that ID.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#570
post #536

Earlier quoted context omitted.

The issue here is not refusing to use a foreign third party. That makes sense. The issue is mandating the use of remote storage and not backing it up. That’s insane. It’s like the most basic amount of preparation you do. It’s recommended to even the smallest of companies specifically because a fire is a risk. That’s gross mismanagement.

> The issue here is not refusing to use a foreign third party. That makes sense. Encrypt before sending to a third party?

Of course you'd encrypt the data before uploading it to a third party, but there's no reason why that third party should be under control of a foreign government. South Korea has more than one data center they can store data inside of, there's no need to trust other governments sigh every byte of data you've gathered, even if there are no known backdoors or flaws in your encryption mechanism (which I'm sure some governments have been looking into for decades).
Post reply on HN