Live data from Hacker News

Danish cloud host says customers ‘lost all data’ after ransomware attack

techcrunch.com

1–10 of 81 posts

Re: Danish cloud host says customers ‘lost all data’ after ransomware attack

#5
post #3
post #2

Time to check the 3-2-1 backups ;)

According to the company the attacker managed to encrypt both the primary and secondary backup systems.

the 1 in the 3-2-1 should be somewhere on premise or at least not directly reachable from the internet.

Think: ssh cron job that copies backups from cloud to cold storage

Re: Danish cloud host says customers ‘lost all data’ after ransomware attack

#6
Yesterday, All those backups seemed a waste of pay. Now my database has gone away. Oh I believe in yesterday.

Suddenly, There's not half the files there used to be, And there's a milestone hanging over me The system crashed so suddenly.

I pushed something wrong What it was I could not say.

Now all my data's gone and I long for yesterday-ay-ay-ay.

Yesterday, The need for back-ups seemed so far away. I knew my data was all here to stay, Now I believe in yesterday.

--

From usenet

My comment on the situation: Online mirrors are fine, but calling them backup is a stretch of the imagination,since you must assume that an event can compromise all data within a domain (be it The Internet, or a physical location).

A true backup must be physically and logically separate.

Re: Danish cloud host says customers ‘lost all data’ after ransomware attack

#7
post #5
post #3

Earlier quoted context omitted.

According to the company the attacker managed to encrypt both the primary and secondary backup systems.

the 1 in the 3-2-1 should be somewhere on premise or at least not directly reachable from the internet. Think: ssh cron job that copies backups from cloud to cold storage

And what if the backup you're copying to cold storage is also encrypted?

How did the saying go? You don't have backups until you've successfully restored from them or something like that. =)

Basically any 3-2-1 system is Schrödinger's backup until you've actually used it.

Re: Danish cloud host says customers ‘lost all data’ after ransomware attack

#8
post #5
post #3

Earlier quoted context omitted.

According to the company the attacker managed to encrypt both the primary and secondary backup systems.

the 1 in the 3-2-1 should be somewhere on premise or at least not directly reachable from the internet. Think: ssh cron job that copies backups from cloud to cold storage

If the data you’re reading is encrypted, you’re still screwed.

Re: Danish cloud host says customers ‘lost all data’ after ransomware attack

#10
post #3
post #2

Time to check the 3-2-1 backups ;)

According to the company the attacker managed to encrypt both the primary and secondary backup systems.

Yes, but as a customer your 3-2-1 strategy should include a backup off that cloud. Not the first time, and won't be the last time a cloud provider has a catastrophic data loss incident. Relying solely on your cloud provider for backups is a risk.
Post reply on HN