Live data from Hacker News

Fire destroys S. Korean government's cloud storage system, no backups available

koreajoongangdaily.joins.com

911–920 of 987 posts

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#911

Earlier quoted context omitted.

Well first of all neither you and I knows the decryption capabilities of the NSA, all we know is that they have hired more cryptologists than the rest of the world combined. Also, it's much easier for an intelligence service to get the hand on a 1kB encryption key than on a PB of data: the former is much easier to exfiltrate without being noticed. And then I don't know why you bring encryption here: pretty much none…

1. More evidence suggests that NSA does not know how to decrypt state-of-the-art ciphers than suggests they do. If they did know, it's far less likely we'd have nation states trying to force Apple and others to provide backdoors for decryption of suspects' personal devices. (Also, as a general rule, I don't put too much stock in the notion that governments are far more competent than the private sector. They're made…

> 2. The operative assumption in my statement is that the government does not possess the key. If they do possess it, all bets are off.

All bets are off from the start. At some point the CIA managed to get their hands on the French nuclear keys

> 3. This thread is about a hypothetical situation in which the Korean government did store backups with a U.S.-based cloud provider

This thread is about using US cloud providers, that's it, you are just moving the goalpost.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#912

Earlier quoted context omitted.

The difference is that you cannot choose who you're sharing a road with while you can usually choose your IT service providers. You could, for instance, choose a cheaper provider and make your own backups or simply accept that you could lose your data. Where people have little or no choice (e.g government agencies, telecoms, internet access providers, credit agencies, etc) or where the blast radius is exceptionally w…

> you cannot choose who you're sharing a road with while you can usually choose your IT service providers You can choose where to eat, but the gov still carrier out food heath and safety inspections. The reason is that it isn't easy for customers to observe these things otherwise. I think the same applies to corporate data handling & storage.

It's a matter of balance. Food safety is potentially about life and death. Backups not so much (except in very specific cases where data regulation is absolutely justifiable).

If any legislation is passed regarding data, I would prefer a broader rule that covers backup as well as interoperability/portability.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#913
post #910
post #737

Earlier quoted context omitted.

In the US, dark fiber will run you around 100k / mile. Thats expensive for anyone even if they can afford it. I worked in HFT for 15 years and we had tons of it.

So that's 5 million bucks for 50 miles? If there are other costs not being accounted for, like paying for the right-of-way that's one thing, but I would think big companies or in this case, a national government, could afford that bill.

Yeah, most large electronic finance companies do this. Lookup “the sniper in mahwah” for some dated but really interesting reading on this game.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#914

Article comments aside, it is entirely unclear to me whether or not there was no backups. Certainly no "external" backups, but potentially "internal" backups. My thinking is that not actually allowing backups and forcing all data there creates a prime target for the PRK folks right? I've been in low level national defense meetings about security where things like "you cannot backup off site" are discussed but there a…

> My thinking is that not actually allowing backups and forcing all data there creates a prime target for the PRK folks right? It's funny that you mention that... https://phrack.org/issues/72/7_md#article

Ouch

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#915

Earlier quoted context omitted.

> I'll also bet the internal audit team slides out of this completely unscathed. They really, really shouldn't. However, if they were shouted down by management (an unfortunately common experience) then it's on management. The trouble is that you can either be effective at internal audit or popular, and lots of CAE's choose the wrong option (but then, people like having jobs so I dunno).

Which begs the question, Does N Korea have governmental whistle-blower laws and/or services? Also, internal audit aren't supposed to be the only audit, they are effectively pre-audit prep for external audit. And the first thing an external auditor should do - ask them probing questions about their systems and process.

That's true, but by their nature, external audits are rarer so one would have expected the IA people to have caught this first.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#916

Earlier quoted context omitted.

The WTC attacks were in the 90s and early 00s and back then, 50 miles of latency was anything but negligible and Azure didn’t exist. I know this because I was working on online systems back then. I also vividly remember 9/11 and the days that followed. We had a satellite dish with multiple receivers (which wasn’t common back then) so had to run a 3rd party Linux box to descramble the single. We watch 24/7 global news…

For backups, latency is far less an issue than bandwidth. Latency is defined by physics (speed of light, through specific conductors or fibres). Bandwidth is determined by technology, which has advanced markedly in the past 25 years. Even a quarter century ago, the bandwidth of a station wagon full of tapes was pretty good, even if the latency was high. Physical media transfer to multiple distant points remains a via…

I’ve covered those points already in other responses. It’s probably worth reading them before assuming I don’t know the differences between the most basic of networking terms.

I was also specifically responding to the GPs point about latency for DB replication. For backups, one wouldn’t have used live replication back then (nor even now, outside of a few enterprise edge cases).

Snowmobile and its ilk was a hugely expensive service by the way. I’ve spent a fair amount of time migrating broadcasters and movie studios to AWS and it was always cheaper and less risky to upload petabytes from the data centre than it was to ship HDDs to AWS. So after conversations with our AWS account manager and running the numbers, we always ended up just uploading the stuff ourselves.

I’m sure there was a customer who benefited from such a service, but we had petabytes and it wasn’t us. And anyone I worked with who had larger storage requirements didn’t use vanilla S3, so I can’t see how Snowmobile would have worked for them either.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#917

Earlier quoted context omitted.

The issue here is not refusing to use a foreign third party. That makes sense. The issue is mandating the use of remote storage and not backing it up. That’s insane. It’s like the most basic amount of preparation you do. It’s recommended to even the smallest of companies specifically because a fire is a risk. That’s gross mismanagement.

I very seriously doubt that the US cares about South Korea's deepest, darkest secrets that much, if at all. Not using a cloud provider is asinine. You can use layered encryption so the expected lifetime of the cryptography is beyond the value of the data...and the US government themselves store data on all 3 of them, to my knowledge. I say US because the only other major cloud providers I know of are in China, and th…

It's quite wild to think how US wouldn't want access to their data on a plate, through AWS/GCP/Azure. You must not be aware of the last decade of news when it comes to US and security.

Re: Fire destroys S. Korean government's cloud storage system, no backups available

#919
post #814

Earlier quoted context omitted.

DWDM per-wavelength costs are way, way lower than that, and, with the optional addition of encryption, perfectly secure and fast enough for disk replication for most storage farms. I've been there and done it.

Assuming that dark fiber is actually dark (without amplifiers/repeaters), I'd wonder how they'd justify the 4 orders of magnitude (99.99%!) profit margin on said fiber. That already includes one order of magnitude between the 12th-of-a-ribbon clad-fiber and opportunistically (when someone already digs the ground up) buried speed pipe with 144-core cable.

Google the term “high frequency trading”
Post reply on HN