Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

671–680 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#672
post #558

Earlier quoted context omitted.

>AWS S3 has pricing of about $0.023/GB/month, which means ... about $20k/month or outright buying hardware capable of storing 850TB for the same $20K one time payment. Gives you some perspective on how overpriced AWS is.

Where are you getting 850TB of enterprise storage for $20k? I had 500TB of object storage priced last year and it came out closer to $300k

136tb for $3k (used gen 2 epyc hardware and refurb <1 hour 16tb hdd's) they're zero risk after firmware validation and 1 full drive read and write.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#673
post #670

Earlier quoted context omitted.

Some foolishly believed that the twin towers were invincible after the 1993 WTC bombing. Before 9/11, most DR (disaster recovery) sites were in Jersey City, NJ just across the river from their main offices in WFC or WTC, or roughly 3-5 miles away. After 9/11, the financial industry adopted a 50+ miles rule.

Jersey City still was fine and 50 miles can be problematic for certain types of backup (failover) protocols. Regular tape backups would be fine but secondary databases can't be that far away (at least not at the time). I remember my boss at WFC saying that the most traffic over the data lines was in the middle of the night due to backups - not when everybody was in the office.

Companies big enough will lay the fibre. 50-100 miles of fibre isn't much if you are a billion dollar business. Even companies like BlackRock who had their own datacenters have since taken up Azure. 50 miles latency is negligible, even for databases.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#674
post #558

Earlier quoted context omitted.

>AWS S3 has pricing of about $0.023/GB/month, which means ... about $20k/month or outright buying hardware capable of storing 850TB for the same $20K one time payment. Gives you some perspective on how overpriced AWS is.

Where are you getting 850TB of enterprise storage for $20k? I had 500TB of object storage priced last year and it came out closer to $300k

That's including the enterprise premium for software, hardware support, and licenses. Building this in-house using open source software (e.g. Ceph) on OEM hardware will be cheaper by an order of magnitude.

You of course need people to maintain it -- the $300k turnkey solution might be the better option depending on current staff.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#675

Earlier quoted context omitted.

Nope: The other way around. If you are of a certain size, you are required to ensure certain criteria. NIS-2 is the EU directive and it more or less maps to ISO27001 which includes risk management against physical catastrophes. https://www.openkritis.de/eu/eu-nis-2-germany.html Of course you can do backups if you are smaller, or comply with such a standard if you so wish.

[flagged]

Well, given that way too many companies in the critical infrastructure sector don't give a fuck about how to keep their systems up and we have been facing a hybrid war from Russia for the last few years that is expected to escalate in a full on NATO hot war in a few years, yes it absolutely does make sense for the government to force such companies to be resilient against Russians.

Just because wherever country you are at doesn't have to prepare for a hot war with Russia doesn't mean we don't have to. When the Russians come in and attack, hell even if they "just" attack Poland with tanks and the rest of us with cyber warfare, the last thing we need is power plants, telco infra, traffic infrastructure or hospitals going out of service because their core systems got hit by ransomware.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#676

Earlier quoted context omitted.

Of course you'd encrypt the data before uploading it to a third party, but there's no reason why that third party should be under control of a foreign government. South Korea has more than one data center they can store data inside of, there's no need to trust other governments sigh every byte of data you've gathered, even if there are no known backdoors or flaws in your encryption mechanism (which I'm sure some gove…

There is a reason that NIST recommends new encryption algorithms from time to time. If you get a copy of ALL government data, in 20 years you might be able to break encryption and get access to ALL government data from 20yr ago, no matter how classified they were, if they were stored in that cloud. Such data might still be valuable, because not all data is published after some period.

That's going away. We are seeing reduced deprecations of crypto algorithms over time AFAICT. The mathematical foundations are becoming better understood and the implementations' assurance levels are improving too. I think we are going up the bathtub curb here.

The value of said data diminishes with time too. You can totally do an off-site cloud backup with mitigation fallbacks should another country become unfriendly. Hell, shard them such that you need n-of-m backups to reconstruct and host each node in a different jurisdiction.

Not that South Korea couldn't have Samsung's Joyent acquisition handle it.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#677

Earlier quoted context omitted.

It might be different “they”s. Putting on my tinfoil hat, whoever was going to be in hot water over the hack burns it down and now the blame shifts from them to whoever manages G-drive and don’t have a backup plan. Not saying I believe this (or even know enough to have an opinion), but it’s always important to not anthropomorphize a large organization. The government isn’t one person (even in totalitarian societies)…

> whoever was going to be in hot water over the hack burns it down and now the blame shifts from them to whoever manages G-drive and don’t have a backup plan. LG is SK firm and manufacturer of hacked hardware and also the batteries that caught fire. Not sure it’s a solid theory just something I took note of while thinking the same

Interesting but same concept applies to organizations.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#678

Earlier quoted context omitted.

More like: your company (or government agency) is critical infrastructure or of a certain size, so there are obligations on how you maintain your records. It’s not like the US or other countries don’t have similar requirements.

[flagged]

It feels like you are being obtuse/arguing in bad faith. Of course there are standards on backups. Most countries have them.

Let's think what regulations does the 'free market' bastion US have on computer systems and data storage...

HIPAA, PCI DSS, CIS, SOC, FIPS, FINRA...

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#679

Earlier quoted context omitted.

Call me a conspiracy theorist, but this kind of mismanagement is intentional by design so powerful people can hide their dirty laundry.

Never attribute to malice what can be attributed to stupidity. There was that time when some high profile company's entire Google Cloud account was destroyed. Backups were on Google Cloud too. No off-site backups.

> Never attribute to malice what can be attributed to stupidity.

Any sufficiently advanced malice is indistinguishable from stupidity.

I don't think there's anything that can't be attributed to stupidity, so the statement is pointless. Besides, it doesn't really matter naming an action stupidity, when the consequences are indistinguishable from that of malice.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#680

Earlier quoted context omitted.

More like: your company (or government agency) is critical infrastructure or of a certain size, so there are obligations on how you maintain your records. It’s not like the US or other countries don’t have similar requirements.

[flagged]

> This is incredible. Government telling me how to backup my data. Incredible.

No more incredible than the government telling you that you need liability insurance in order to drive a car. Do you think that is justifiable?

Post reply on HN