8 ms·
Agree completely that it's absolute wild to run such a system without backups. But at this point no government should keep critical data on foreign cloud storag
by eCa 1y ago
Agree completely that it's absolute wild to run such a system without backups. But at this point no government should keep critical data on foreign cloud storage.
- stogot 1y agoWhy not? If the region is in country, encrypted, and with proven security attestations validated by third parties, a backup to a cloud storage would be incredibly wise. Otherwise we might end up reading an article about a fire burning down a single data center
- g-b-r 1y agoAnd which organization has every file, from each of their applications using the cloud, encrypted *before* it is sent to the cloud?
- crazygringo 1y agoExactly. Like, don't store it in the cloud of an enemy country of course. But if it's encrypted and you're keeping a live backup in a second country with a second company, ideally with a different geopolitical alignment, I don't see the problem.
- OvbiousError 1y agoEnemy country in the current geopolitical climate is an interesting take. Doesn't sound like a great idea to me tbh.
- deaddodo 1y agoThere are a lot of gray relations out there, but there’s almost no way you could morph the current US/SK relations to one of hostility; beyond a negligible minority of citizens in either being super vocal for some perceived slights.
- 9dev 1y agoTrump will find a way, just as he did with Canada for example (i mean, Canada of all places). Things are way more in flux than they used to be. There’s no stability anymore.
- shantara 1y agoA year ago, I would have easily claimed the same thing about Denmark.
- throwaway2037 1y agoI don't follow. Can you share more context?
- marcosdumay 1y agoThe US is threatening to invade Greenland, what means active war with Denmark.
- throwaway2037 1y agoGreat point! I forgot that Greenland is not (yet) an independent nation. It is still a part of Denmark.
- shakna 1y agoMicrosoft has already testified that the American government maintains access to their data centres, in all regions. It likely applies to all American cloud companies. America is not a stable ally, and has a history of spying on friends. So unless the whole of your backup is encrypted offline, and you trust the NSA to never break the encryption you chose, its a national security risk.
- bink 1y agoNot only does the NSA break encryption but they actually sabotage algorithms to make them easier to break when used.
- edoceo 1y agoCan the NSA break the Ed25519 stuff? Like the crypto_box from libsodium?
- immibis 1y agoed25519 (and ec25519) are generally understood not to be backdoored by the NSA, or weak in any known sense. The lack of a backdoor can be proven by choosing parameters according to straightforward reasons that do not allow the possibility for the chooser to insert a backdoor. The curve25519 parameters have good reasons why they are chosen. By contrast, Dual_EC_DRBG contains two random-looking numbers, which the NSA pinky-swears were completely random, but actually they generated them using a private key that only the NSA knows. Since the NSA got to choose any numbers to fit there, they could do that. When something is, like, "the greatest prime number less than 2^255" you can't just insert the public key of your private key into that slot because the chance the NSA can generate a private key whose public key just happens to match the greatest prime number less than 2^255 is zero. These are called "nothing up my sleeve numbers". This doesn't prove the algorithm isn't just plain old weak, but nobody's been able to break it, either. Or find any reason why it would be breakable. Elliptic curves being unbreakable rests on the discrete logarithm of a random-looking permutation being impossible to efficiently solve, in a similar way to how RSA being unbreakable relies on nobody being able to efficiently factorize very big numbers. The best known algorithms for solving discrete logarithm require O(sqrt(n)) time, so you get half the bits of security as the length of the numbers involved; a 256-bit curve offers 128 bits of security, which is generally considered sufficient. (Unlike RSA, you can't just arbitrarily increase the bit length but have to choose a completely new curve for each bit length, unfortunately. ed25519 will always be 255 bits, and if a different length is needed, it'll be similar but called something else. On the other hand, that makes it very easy to standardize.)
- neom 1y agoGood thing Korea has cloud providers, apparently Kakao has even gone...beyond the cloud! https://kakaocloud.com/ https://kakaocloud.com/ https://www.nhncloud.com/ https://www.nhncloud.com/ https://cloud.kt.com/ https://cloud.kt.com/ To name a few.
- alephnerd 1y agoThey are overwhelmingly whitelabeled providers. For example, Samsung SDI Cloud (the largest "Korean" cloud) is an AWS white label. Korea is great at a lot of engineering disciplines. Sadly, software is not one of them, though it's slowly changing. There was a similar issue a couple years ago where the government's internal intranet was down a couple days because someone deployed a switch in front of outbound connections without anyone noticing. It's not a talent problem but a management problem - similar to Japan's issues, which is unsurprising as Korean institutions and organizations are heavily based on Japanese ones from back in the JETRO era.
- skissane 1y agoI spent a week of my life at a major insurance company in Seoul once, and the military style security, the obsession with corporate espionage, when all they were working on was an internal corporate portal for an insurance company… The developers had to use machines with no Internet access, I wasn’t allowed to bring my laptop with me lest I use it to steal their precious code. A South Korean colleague told me it was this way because South Korean corporate management is stuffed full of ex-military officers who take the attitudes they get from defending against the North with them into the corporate world; no wonder the project was having so many technical problems-but I couldn’t really solve them, because ultimately the problems weren’t really technical
- dtech 1y agoEncrypted backups would have saved a lot of pain here
- deleted 1y ago[deleted]
- edoceo 1y agoAny backup would do at this point. I think the most best is: encrypted, off-site & tested monthly.
- CamouflagedKiwi 1y agoAnd yet here is an example where keeping critical data off public cloud storage has been significantly worse for them in the short term. Not that they should just go all in on it, but an encrypted copy on S3 or GCS would seem really useful right about now.
- vladms 1y agoYou can do a bad job with public or private cloud. What if they would have had the backup and lost the encryption key? Cost wise probably having even a Korean different data center backup would not have been huge effort, but not doing it exposed them to a huge risk.
- deleted 1y ago[deleted]
- Cthulhu_ 1y agoThen they didn't have a correct backup to begin with; for high profile organizations like that, they need to practice outages and data recovery as routine. ...in an ideal world anyway, in practice I've never seen a disaster recovery training. I've had fire drills plenty of times though.
- hinkley 1y agoWe’ve had Byzantine crypto key solutions since at least 2007 when I was evaluating one for code signing for commercial airplanes. You could put an access key on k:n smart cards, so that you could extract it from one piece of hardware to put on another, or you could put the actual key on the cards so burning down the data center only lost you the key if you locked half the card holders in before setting it on fire.
- n5NOJwkc7kRC 1y agoSSS is from 1979. https://en.wikipedia.org/wiki/Shamir%27s_secret_sharing https://en.wikipedia.org/wiki/Shamir%27s_secret_sharing
- JumpCrisscross 1y ago> no government should keep critical data on foreign cloud storage Primary? No. Back-up? These guys couldn’t provision a back-up for their on-site data. Why do you think it was competently encrypted?
- jacquesm 1y agoThey fucked up, that much is clear but the should not have kept that data on foreign cloud storage regardless. It's not like there are only two choices here.
- JumpCrisscross 1y ago> the should not have kept that data on foreign cloud storage regardless. It's not like there are only two choices here Doesn't have to be an American provider (Though anyone else probably increases Seoul's security cross section. America is already its security guarantor, with tens of thousands of troops stationed in Korea.) And doesn't have to be permanent. Ship encrypted copies to S3 while you get your hardenede-bunker domestic option constructed. Still beats the mess that's about to come for South Korea's population.
- jacquesm 1y agoI'm aware of a big cloud services provider (I won't name any names but it was IBM) that lost a fairly large amount of data. Permanently. So that too isn't a guarantee. They simply should have made local and off-line backups, that's the gold standard, and to ensure that those backups are complete and can be used to restore from scratch to a complete working service.
- nicolas_17 1y agoDigitalOcean lost some of my files in their object storage too: https://status.digitalocean.com/incidents/tmnyhddpkyvf https://status.digitalocean.com/incidents/tmnyhddpkyvf Using a commercial provider is not a guarantee.
- bombcar 1y agoIf you can’t encrypt your backups such that you could store them tatooed on Putin’s ass, you need to learn about backups more.
- kube-system 1y agoGovernments need to worry about 1. future cryptography attacks that do not exist today 2. Availability of data 3. The legal environment of the data Encryption is not a panacea that solves every problem
- charlieyu1 1y agoYou don’t need cloud when you have the data centre, just backups in physical locations somewhere else
- catlifeonmars 1y agoOthers have pointed out: you need uptime too. So a single data center on the same electric grid or geographic fault zone wouldn’t really cut it. This is one of those times where it sucks to be a small country (geographically).
- bell-cot 1y ago> so a single data center on the same electrical grid or geographic... Yes, but your backup DC's can have diesel generators and a few weeks of on-site fuel. It has some quakes - but quake-resistant DC's exist, and SK is big enough to site 3 DC's at the corners of an equilateral triangle with 250km edges. Similar for typhoons. Invading NK armies and nuclear missiles are tougher problems - but having more geography would be of pretty limited use against those.
- sneak 1y agoIt's 2025. Encryption is a thing now. You can store anything you want on foreign cloud storage. I'd give my backups to the FSB.
- justinclift 1y ago> I'd give my backups to the FSB. Until you need them - like with the article here ;) - then the FSB says "only if you do these specific favours for us first...".
- Cthulhu_ 1y agoThere's certifications too, which you don't get unless you conform to for example EU data protection laws. On paper anyway. But these have opened up Amazon and Azure to e.g. Dutch government agencies, the tax office will be migrating to Office365 for example.
- tirant 1y agoEncryption does not ensure any type of availability.
- preisschild 1y agoEspecially on US cloud storage. The data is never safe thanks to the US Cloud Act.
- HardCodedBias 1y agoWhy not? Has there been any interruption in service?