Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

791–800 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#792
post #769

Earlier quoted context omitted.

Not the same country but another example of a culturally similar attitude towards shame over failure: In Japan in 1985, Flight 123, a massive Boeing 747 carrying 524 people, lost control shortly after takeoff from Tokyo en route to Osaka. The plane's aft pressure bulkhead catastrophically exploded, causing total decompression at the high altitude, severing all four of the massive plane's hydraulic stabilizer systems…

Obligatory long form link: https://admiralcloudberg.medium.com/fire-on-the-mountain-the...

Wish I'd thought to include it myself!

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#793

Earlier quoted context omitted.

Why not?

As of today, there's no way to prove the security of any available cryptosystem. Let me say that differently: for all we know, ALL currently available cryptosystems can be easily cracked by some unpublished techniques. The only sort-of exception to that requires quantum communication, which is nowhere near practicability on the scale required. The only evidence we have that the cryptography that we commonly use is ac…

One-time pad is provable secure. But it is not useful for backups, of course.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#794
post #536

Earlier quoted context omitted.

The issue here is not refusing to use a foreign third party. That makes sense. The issue is mandating the use of remote storage and not backing it up. That’s insane. It’s like the most basic amount of preparation you do. It’s recommended to even the smallest of companies specifically because a fire is a risk. That’s gross mismanagement.

> The issue here is not refusing to use a foreign third party. That makes sense. Encrypt before sending to a third party?

> Encrypt before sending to a third party?

That sounds great, as long as nobody makes any mistake. It could be a bug on the RNG which generates the encryption keys. It could be a software or hardware defect which leaks information about the keys (IIRC, some cryptographic system are really sensitive about this, a single bit flip during encryption could make it possible to obtain the private key). It could be someone carelessly leaving the keys in an object storage bucket or source code repository. Or it could be deliberate espionage to obtain the keys.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#795

The government official who insisted that commercial AWS/GCP/Azure couldn't possibly be trusted with keeping the information will be keeping their head low for a few days then... "The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for extern…

I mean he's still right about AWS etc. with the current US Administration and probably all that will follow - but that doesn't excuse not keeping backups.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#796

Earlier quoted context omitted.

Nothing increases the risk of servers catching fire like government investigators showing up to investigate allegations that North Korea hacked the servers.

>This file contains the complete set of papers, except for a number of secret documents, a few others which are part of still active files, some correspondence lost in the floods of 1967... >Was 1967 a particularly bad winter? >No, a marvellous winter. We lost no end of embarrassing files.

Yes minister! Great show that no one in the US has heard of which is a shame.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#797

Earlier quoted context omitted.

Yes, and US bad at everything else.

The US economy is one of the world's most diverse in terms of exports: https://oec.world/en/visualize/tree_map/hs92/export/usa/all/... Side note: Why is there so much fact-free anti-US sentiment on HN?

Orange man bad

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#798

Earlier quoted context omitted.

You make an incorrect assumption about my assumptions. Faster computers or decryption techniques will never fundamentally "break" symmetric encryption. There's no discrete logarithm or factorization problem to speed up. Someone might find ways to make for example AES key recovery somewhat faster, but the margin of safety in those cases is still incredibly vast. In the end there's such an unfathomably vast key space t…

You're also assuming nobody finds a fundamental flaw in AES that allows data to be decrypted without knowing the key and much faster than brute force. It's pretty likely there isn't one, but a tiny probability multiplied by a massive impact can still land on the side of "don't do it".

I'm not. It's just that the math behind AES is very fundamental and incredibly solid compared to a lot of other (asymmetric) cryptographic schemes in use today. Calling the chances of it tiny instead of nearly nonexistent sabotages almost all risk assessments. Especially if it then overshadows other parts of that assessment (like data loss). Even if someone found "new math" and it takes very optimistically 60 years, of what value is that data then? It's not an useful risk assessment if you assess it over infinite time.

But you could also go with something like OTP and then it's actually fundamentally unbreakable. If the data truly is that important, surely double the storage cost would also be worth it.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#799
post #741

Earlier quoted context omitted.

Wait what?

There are all sorts of crazy ways of getting data out of even air-gapped machines, providing you are willing to accept extremely low data rates to overcome attenuation. Even with million-to-one signal-to-noise ratio, you can get significant amounts of key data out in a few weeks. Jiggling disk heads, modulating fan rates, increasing and decreasing power draw... all are potential information leaks.

> There are all sorts of crazy ways of getting data out of even air-gapped machines.

Chelsea Manning apparently did it by walking in and out of the facility with a CD marked 'Lady Gaga'. Repeatedly

https://www.theguardian.com/world/2010/nov/28/how-us-embassy...

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#800

"The stored data amounts to 858TB (terabytes), equivalent to 449.5 billion A4 sheets" Just so we can all visualise this in an understandable way, if laid end-to-end how many times round the world would the A4 sheets go? And what is their total area in football fields?

I know you want to think of this is as a lot of data, but this really isn't that much. It'll cost less than a few thousand to keep a copy in glacier on s3, or a single IT dude could build a NAS at his home that could easily hold this data for a few tens of thousands tops. The entire thing.
Post reply on HN