Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

681–690 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#681

Earlier quoted context omitted.

[flagged]

It feels like you are being obtuse/arguing in bad faith. Of course there are standards on backups. Most countries have them. Let's think what regulations does the 'free market' bastion US have on computer systems and data storage... HIPAA, PCI DSS, CIS, SOC, FIPS, FINRA...

> HIPAA, PCI DSS, CIS, SOC, FIPS, FINRA

Those are related to _someone else's_ data handling.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#682

Earlier quoted context omitted.

[flagged]

Well, given that way too many companies in the critical infrastructure sector don't give a fuck about how to keep their systems up and we have been facing a hybrid war from Russia for the last few years that is expected to escalate in a full on NATO hot war in a few years, yes it absolutely does make sense for the government to force such companies to be resilient against Russians. Just because wherever country you a…

> it absolutely does make sense for the government to force such companies

Problem is, a) governments are infiltrated by russian assets and b) governments are known to enforce detrimental IT regulations. Germany especially so.

> power plants, telco infra, traffic infrastructure or hospitals

Their system _will_ get hit by ransomware or APTs. It is not possible to mandate common sense or proper IT practices, no matter how strict the law. See the recent incident in South Korea with burned down data center with no backups.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#683

Earlier quoted context omitted.

Call me a conspiracy theorist, but this kind of mismanagement is intentional by design so powerful people can hide their dirty laundry.

Never attribute to malice what can be attributed to stupidity. There was that time when some high profile company's entire Google Cloud account was destroyed. Backups were on Google Cloud too. No off-site backups.

Hanlon's Razor is such an overused meme/trope that it's become meaningless.

It's a fallacy to assume that malice is never a form of stupidity/folly. An evil person fails to understand what is truly good because of some kind of folly, e.g. refusing to internally acknowledge the evil consequences of evil actions. There is no clean evil-vs-stupid dichotomy. E.g. is a drunk driver who kill someone with drunk driving stupid or evil? The dangers of drunk driving are well-known, so what about both?

Additionally, we are talking about a system/organization, not a person with a unified will/agenda. There could indeed be an evil person in an organization that wants the organization to do stupid things (not backup properly) in order to be able to hide his misdeeds.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#684

Earlier quoted context omitted.

Nope: The other way around. If you are of a certain size, you are required to ensure certain criteria. NIS-2 is the EU directive and it more or less maps to ISO27001 which includes risk management against physical catastrophes. https://www.openkritis.de/eu/eu-nis-2-germany.html Of course you can do backups if you are smaller, or comply with such a standard if you so wish.

[flagged]

Is it? It would be incredible if the government didn’t have specific requirements for critical infrastructure.

Say you’re an energy company and an incident could mean that a big part of the country is without power, or you’re a large bank and you can’t process payroll for millions of workers. They’re ability to recover quickly and completely matters. Just recently in Australia an incident at Optus, a large phone company, prevented thousands of people from making emergency calls for several hours. Several people died including a child.

The people should require these providers behave responsibly. And the way the people do that is with a government.

Companies behave poorly all the time. Red tape isn’t always bad.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#685

Earlier quoted context omitted.

Well, given that way too many companies in the critical infrastructure sector don't give a fuck about how to keep their systems up and we have been facing a hybrid war from Russia for the last few years that is expected to escalate in a full on NATO hot war in a few years, yes it absolutely does make sense for the government to force such companies to be resilient against Russians. Just because wherever country you a…

> it absolutely does make sense for the government to force such companies Problem is, a) governments are infiltrated by russian assets and b) governments are known to enforce detrimental IT regulations. Germany especially so. > power plants, telco infra, traffic infrastructure or hospitals Their system _will_ get hit by ransomware or APTs. It is not possible to mandate common sense or proper IT practices, no matter…

[deleted]

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#686
post #659

Earlier quoted context omitted.

Back when I worked for Mozilla, I had the chance to go to Seoul to meet with various companies and some governmental ministries. This was when Korean banks and ecommerce sites required Internet Explorer and Active-X controls for secure transactions. This meant that MacOS users or Linux users couldnt do secure transactions in Korea without emulating Win/IE.

What was the outcome of these meetings? Have they switched to Firefox?

They never did afaict. Eventually smartphones became ubiquitous and I think most S. Koreans bank on their phones using apps. As for those who bank on computer, I dont know what happened when Active-X was deprecated. It was a poor decision by the S. Korean govt. to hang their hat on that technology.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#687

Earlier quoted context omitted.

Well, given that way too many companies in the critical infrastructure sector don't give a fuck about how to keep their systems up and we have been facing a hybrid war from Russia for the last few years that is expected to escalate in a full on NATO hot war in a few years, yes it absolutely does make sense for the government to force such companies to be resilient against Russians. Just because wherever country you a…

> it absolutely does make sense for the government to force such companies Problem is, a) governments are infiltrated by russian assets and b) governments are known to enforce detrimental IT regulations. Germany especially so. > power plants, telco infra, traffic infrastructure or hospitals Their system _will_ get hit by ransomware or APTs. It is not possible to mandate common sense or proper IT practices, no matter…

Government isn’t perfect but I’d be interested to know what alternative you propose?

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#688

Earlier quoted context omitted.

Well, given that way too many companies in the critical infrastructure sector don't give a fuck about how to keep their systems up and we have been facing a hybrid war from Russia for the last few years that is expected to escalate in a full on NATO hot war in a few years, yes it absolutely does make sense for the government to force such companies to be resilient against Russians. Just because wherever country you a…

> it absolutely does make sense for the government to force such companies Problem is, a) governments are infiltrated by russian assets and b) governments are known to enforce detrimental IT regulations. Germany especially so. > power plants, telco infra, traffic infrastructure or hospitals Their system _will_ get hit by ransomware or APTs. It is not possible to mandate common sense or proper IT practices, no matter…

> Problem is, a) governments are infiltrated by russian assets and b) governments are known to enforce detrimental IT regulations. Germany especially so.

The regulations are a framework called "BSI Grundschutz" and all parts are freely available for everyone [1]. Even if our government were fully corrupted by Russia like Orban's Hungary - just look at the regulations on their face values and tell me what exactly you would see as "detrimental" or against best practice?

> It is not possible to mandate common sense or proper IT practices, no matter how strict the law. See the recent incident in South Korea with burned down data center with no backups.

I think it actually is. The BSI Grundschutz criteria tend to feel "checkboxy", but if you tick all the checkboxes you'll end up with a pretty resilient system. And yes, I've been on the implementing side.

The thing is, even if you're not fully compliant with BSI Grundschutz... if you just follow parts of it in your architecture, your security and resilience posture is already much stronger than much of the competition.

[1] https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisati...

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#689

Earlier quoted context omitted.

AWS? Linus Tech Tips has run multiple petabyte servers in their server closet just for sponsor money and for the cool of it. No need to outsource your national infrastructure to foreign governments, a moderate (in government terms) investment in a few racks across the country could've replicated everything for maybe half a year's worth of Amazon subscription fees.

Exactly, everyone here on hackernews is talking about Azure/AWS/GCP as if it was the only correct way to store data. Americans are too self centered, it's quite crazy.

Yeah the comments here are slightly surreal; the issue was that they didn’t have an off-site backup at all, not that it wasn’t on AWS or whatever.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#690

The government official who insisted that commercial AWS/GCP/Azure couldn't possibly be trusted with keeping the information will be keeping their head low for a few days then... "The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for extern…

I know there is legit hate for VMWare/Broadcom but there is a legit case to be made for VCF with an equivalent DR setup where you have replication enabled by Superna and Dell PowerProtect Data Domain protecting both local and remote with Thales Luna K160 KMIP for the data at rest encryption for the vSAN. To add, use F710s, H710s and then add ObjectScale storage for your Kubernetes workloads. This setup repatriates yo…

This reads very similar to the Turbo Encabulator video.
Post reply on HN