3 ms·
Then what can you trust? Your own hardware? What about if they go bad? Make multiple copies? How many? And what are the implications of managing multiple local
by artellectual 6y ago
Then what can you trust? Your own hardware? What about if they go bad? Make multiple copies? How many? And what are the implications of managing multiple local backups scattered everywhere on your own hardware? What are the costs involved? How many people should handle that? Who should hold the encryption key? How many keys? What happens if key is exposed and we have to regenerate?
At the end of the day every system has risks. It’s about what is acceptable. It’s engineer’s job to reduce risk. In my case I didn’t say what is right or wrong I just mentioned that increased risk is coming at regulator’s decision they should acknowledge and sign a piece of paper.
When you make decisions there are repercussions, you have to accept. That’s all.
- nalekberov 6y agoOkay step by step: You can trust your own hardware more than someone else’s hardware. Everything can go bad, but if you physically have access, it increases the probability of recovery. (Since you care more) Usually one copy where you have easy physical access and sure other than certain people cannot access this room (has all the required indicators and alarms in case of high temperature etc) another one within the space of governmentally approved area (usually this area has the least probably of seeing natural disaster) should be enough. Costs? Data security cannot be subject to tradeoffs. Usually two people own two physical keys to the backup machine, without one , the machine should not allow any access (in case one of them threatened to give up the data). you ought to keep the keys in secure place. It’s firstly information security engineer’s responsibility to take care of the Information security.
- artellectual 6y agoOr you can just pay for all that stuff to be managed. That's the whole point of the cloud. Everything you just listed is done by our cloud provider.
- ric2b 6y ago> Costs? Data security cannot be subject to tradeoffs. That's obviously ridiculous. Should I hire an army to protect my server room? Should I hire the entire NSA to do a 2 decade long audit on my code, hardware, employees, etc, before I launch the service?
- nalekberov 6y agoI don’t understand what are you talking about. Honestly.