6 ms·
Backups should be far away, too. Apparently some companies lost everything on 9/11 because their backups were in the other tower.
by thanatos519 1y ago
Backups should be far away, too. Apparently some companies lost everything on 9/11 because their backups were in the other tower.
- szundi 1y ago[dead]
- zwnow 1y agoFunnily enough, Germany has laws for where you are allowed to store backups exactly due to these kinda issues. Fire, flood, earthquake, tornadoes, whatever you name, backups need to be stored with appropriate security in mind.
- egorfine 1y agoGermany, of course. Like my company needs government permission to store backups.
- leipert 1y agoMore like: your company (or government agency) is critical infrastructure or of a certain size, so there are obligations on how you maintain your records. It’s not like the US or other countries don’t have similar requirements.
- egorfine 1y ago[flagged]
- leipert 1y agoNope: The other way around. If you are of a certain size, you are required to ensure certain criteria. NIS-2 is the EU directive and it more or less maps to ISO27001 which includes risk management against physical catastrophes. https://www.openkritis.de/eu/eu-nis-2-germany.html https://www.openkritis.de/eu/eu-nis-2-germany.html Of course you can do backups if you are smaller, or comply with such a standard if you so wish.
- egorfine 1y ago[flagged]
- mschuster91 1y agoWell, given that way too many companies in the critical infrastructure sector don't give a fuck about how to keep their systems up and we have been facing a hybrid war from Russia for the last few years that is expected to escalate in a full on NATO hot war in a few years, yes it absolutely does make sense for the government to force such companies to be resilient against Russians. Just because wherever country you are at doesn't have to prepare for a hot war with Russia doesn't mean we don't have to. When the Russians come in and attack, hell even if they "just" attack Poland with tanks and the rest of us with cyber warfare, the last thing we need is power plants, telco infra, traffic infrastructure or hospitals going out of service because their core systems got hit by ransomware.
- egorfine 1y ago> it absolutely does make sense for the government to force such companies Problem is, a) governments are infiltrated by russian assets and b) governments are known to enforce detrimental IT regulations. Germany especially so. > power plants, telco infra, traffic infrastructure or hospitals Their system _will_ get hit by ransomware or APTs. It is not possible to mandate common sense or proper IT practices, no matter how strict the law. See the recent incident in South Korea with burned down data center with no backups.
- deleted 1y ago[deleted]
- hiharryhere 1y agoGovernment isn’t perfect but I’d be interested to know what alternative you propose?
- 1y ago
- zestyping 1y ago> This is incredible. Government telling me how to backup my data. Incredible. No more incredible than the government telling you that you need liability insurance in order to drive a car. Do you think that is justifiable?
- fauigerzigerk 1y agoThe difference is that you cannot choose who you're sharing a road with while you can usually choose your IT service providers. You could, for instance, choose a cheaper provider and make your own backups or simply accept that you could lose your data. Where people have little or no choice (e.g government agencies, telecoms, internet access providers, credit agencies, etc) or where the blast radius is exceptionally wide, I do find it justifiable to mandate safety and security standards.
- johannes1234321 1y agoLosing data is mostly(*) fine if you are a small business. If a major bank loses it's data it is a major problem as it may impact a huge number of customers and an existential way, when all money is "gone" (*) From state's perspective there is still a problem: tax audits, bad if everybody avoids them by "accidental" data loss
- fauigerzigerk 1y agoAs I said, a wide blast radius is a justification and banks are already regulated accordingly. A general obligation to keep financial records exists as well.
- Chris2048 1y ago> you cannot choose who you're sharing a road with while you can usually choose your IT service providers You can choose where to eat, but the gov still carrier out food heath and safety inspections. The reason is that it isn't easy for customers to observe these things otherwise. I think the same applies to corporate data handling & storage.
- flumpcakes 1y agoIt feels like you are being obtuse/arguing in bad faith. Of course there are standards on backups. Most countries have them. Let's think what regulations does the 'free market' bastion US have on computer systems and data storage... HIPAA, PCI DSS, CIS, SOC, FIPS, FINRA...
- Skeime 1y ago(Without knowing the precise nature of these laws) I would expect that they don't forbid you to store backups elsewhere. It's just that they mandate that certain types of data be backed up in sufficiently secure and independent locations. If you want to have an additional backup (or backups of data not covered by the law) in a more convenient location, you still can.
- egorfine 1y ago> sufficiently secure and independent locations This kind of provision requires enforcement and verification. Thus, a tech spec for the backup procedure. Knowing Germany good enough, I'd say that these tech spec would be detrimental for the actual safety of the backup.
- greybeard69 1y agowild speculation and conjecture
- egorfine 1y agoAgree. It is based on my experience with German bureaucracy.
- f1shy 1y agoNot wild. When you live in Germany and are asked to send a FAX (and not a mail, please). Or a digital birth certificate is not accepted until you come with lawyers, or banks not willing to operate with Apple pay, just to name few.. Speculation, yes, but not at all wild
- __bjoernd 11mo agoI'm German and in my 45 years of being so have never been required to send a fax. Snail mail yes, but never a fax.
- hdgvhicv 1y agoNo it doesn’t. It does however need to follow the appropiate standards commensurate with your size and criticality. Feel free to exceed them.
- Chris2048 1y agoCertain data records need to be legally retained for certain amounts of time; Other sensitive data (e.g. PII) have security requirements. Why wouldn't government mandate storage requirements given the above?
- tooltalk 1y agoSome foolishly believed that the twin towers were invincible after the 1993 WTC bombing. Before 9/11, most DR (disaster recovery) sites were in Jersey City, NJ just across the river from their main offices in WFC or WTC, or roughly 3-5 miles away. After 9/11, the financial industry adopted a 50+ miles rule.
- AdamN 1y agoJersey City still was fine and 50 miles can be problematic for certain types of backup (failover) protocols. Regular tape backups would be fine but secondary databases can't be that far away (at least not at the time). I remember my boss at WFC saying that the most traffic over the data lines was in the middle of the night due to backups - not when everybody was in the office.
- flumpcakes 1y agoCompanies big enough will lay the fibre. 50-100 miles of fibre isn't much if you are a billion dollar business. Even companies like BlackRock who had their own datacenters have since taken up Azure. 50 miles latency is negligible, even for databases.
- hnlmorg 1y agoThe WTC attacks were in the 90s and early 00s and back then, 50 miles of latency was anything but negligible and Azure didn’t exist. I know this because I was working on online systems back then. I also vividly remember 9/11 and the days that followed. We had a satellite dish with multiple receivers (which wasn’t common back then) so had to run a 3rd party Linux box to descramble the single. We watch 24/7 global news on a crappy 5:4 CRT running Windows ME during the attack. Even in the UK, it was a somber and sobering experience.
- osivertsson 1y agoLaws of physics hasn't changed since the early 00s though, we could build very low latency point to point links back then too.
- IAmBroom 1y agoThey deserved to lose everything... except the human lives, of course. That's like storing lifeboats in the bilge section of the ship, so they won't get damaged by storms.