Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

891–900 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#891

The government official who insisted that commercial AWS/GCP/Azure couldn't possibly be trusted with keeping the information will be keeping their head low for a few days then... "The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for extern…

The issue here is not refusing to use a foreign third party. That makes sense. The issue is mandating the use of remote storage and not backing it up. That’s insane. It’s like the most basic amount of preparation you do. It’s recommended to even the smallest of companies specifically because a fire is a risk. That’s gross mismanagement.

The issue is without profit incentive of course it isn’t X (backed up, redundant, highly available, whatever other aspect is optimized away by accountants).

Having worked a great deal inside of aws on these things aws provides literally every conceivable level of customer managed security down to customer owned and keyed datacenters operated by aws, with master key HSMs owned, purchased by the customer, with customer managed key hierarchies at all levels and detailed audit logs of everything done by everything including aws itself. The security assurance of aws is far and away beyond what even the most sophisticated state actor infrastructure does and is more modern to boot - because it’s profit incentive drives that.

Most likely this was not about national security than about nationalism. They’re easily confused but that’s fallacious. And they earned the dividends of fallacious thinking.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#892

Earlier quoted context omitted.

I spent a week of my life at a major insurance company in Seoul once, and the military style security, the obsession with corporate espionage, when all they were working on was an internal corporate portal for an insurance company… The developers had to use machines with no Internet access, I wasn’t allowed to bring my laptop with me lest I use it to steal their precious code. A South Korean colleague told me it was…

> South Korean corporate management is stuffed full of ex-military officers For those unaware, all "able-bodied" South Korean men are required to do about two years of military service. This sentence doesn't do much for me. Also, please remember that Germany also had required military service until quite recently. That means anyone "old" (over 40) and doing corp mgmt was probably also a military officer.

All able bodied men don't become officers.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#894

"The stored data amounts to 858TB (terabytes), equivalent to 449.5 billion A4 sheets" Just so we can all visualise this in an understandable way, if laid end-to-end how many times round the world would the A4 sheets go? And what is their total area in football fields?

I know you want to think of this is as a lot of data, but this really isn't that much. It'll cost less than a few thousand to keep a copy in glacier on s3, or a single IT dude could build a NAS at his home that could easily hold this data for a few tens of thousands tops. The entire thing.

Close to 1 petabyte for home server is quite much, honestly. It will cost tens of thousands dollars. But yeah, on government level, nothing.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#895

Earlier quoted context omitted.

> I'll also bet the internal audit team slides out of this completely unscathed. They really, really shouldn't. However, if they were shouted down by management (an unfortunately common experience) then it's on management. The trouble is that you can either be effective at internal audit or popular, and lots of CAE's choose the wrong option (but then, people like having jobs so I dunno).

Which begs the question, Does N Korea have governmental whistle-blower laws and/or services? Also, internal audit aren't supposed to be the only audit, they are effectively pre-audit prep for external audit. And the first thing an external auditor should do - ask them probing questions about their systems and process.

Wrong Korea, this is South Korea

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#896
A little more informative source:

https://www.datacenterdynamics.com/en/news/858tb-of-governme...

- G-drive stands for Government Drive

- The incident was caused due to Lithium battery fire

- The drive was of 858TB capacity

- No backup because “The G-Drive couldn’t have a backup system due to its large capacity” (!!)

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#897

Earlier quoted context omitted.

The issue here is not refusing to use a foreign third party. That makes sense. The issue is mandating the use of remote storage and not backing it up. That’s insane. It’s like the most basic amount of preparation you do. It’s recommended to even the smallest of companies specifically because a fire is a risk. That’s gross mismanagement.

This. Speaking specifically from the IT side of things, an employer or customer refusing to do backups is the biggest red flag I can get, an immediate warning to run the fuck away before you get blamed for their failure, stego-tech kind of situation. That being said, I can likely guess where this ends up going: * Current IT staff and management are almost certainly scapegoated for “allowing this to happen”, despite t…

There's a pretty big possibility it comes down to acquisition and cost saving from politicians in charge of the purse strings. I can all but guarantee that the systems administrators and even technical managers had suggested, recommended and all but begged for the resources for a redundant/backup system in a separate physical location were denied because it would double the expense.

This isn't to preclude major ignorance in terms of those in the technology departments themselves. Having worked in/around govt projects a number of times, you will see some "interesting" opinions and positions. Especially around (mis)understanding security.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#898

Earlier quoted context omitted.

> * Everyone involved is unlikely to find work again anytime soon once names are bandied about in investigations They might (MIGHT) get fired from their government jobs, but I'll bet they land in consulting shops because of their knowledge of how the government's IT teams operate. I'll also bet the internal audit team slides out of this completely unscathed.

> I'll also bet the internal audit team slides out of this completely unscathed. They really, really shouldn't. However, if they were shouted down by management (an unfortunately common experience) then it's on management. The trouble is that you can either be effective at internal audit or popular, and lots of CAE's choose the wrong option (but then, people like having jobs so I dunno).

Likely it wasn't even (direct) management, but the budgeting handled by politicians and/or political appointees.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#900

Earlier quoted context omitted.

The US economy is one of the world's most diverse in terms of exports: https://oec.world/en/visualize/tree_map/hs92/export/usa/all/... Side note: Why is there so much fact-free anti-US sentiment on HN?

Orange man bad

I'd say it is more because "Orange man says we are bad at X, but only he can make X great again™".

People start believing we can't do anything at all.

Post reply on HN