Top
Best
New

Posted by berkeleyjunk 1 day ago

AWS says it can't restore some data from mideast facilities struck by Iran(www.wsj.com)
https://archive.is/Ay7RJ
445 points | 374 commentspage 5
HDBaseT 1 day ago|
[dead]
tornado134 13 hours ago||
[dead]
shevy-java 15 hours ago||
[flagged]
Cyclone_ 15 hours ago||
[flagged]
mitxela 13 hours ago||
Israel had been trying to get every president to bomb Iran for decades. There's a reason they wouldn't do it themselves. They finally got a president stupid enough to listen.
drnick1 14 hours ago||
[flagged]
carefree-bob 14 hours ago|||
This is not exactly a nuanced view of the conflict, and in either case, the fact that you don't like that someone on the other side of the world is chanting death to America doesn't give you a bonus card for a free attack.

Seriously, it's like people, when deciding whether to launch a war or not, are not thinking "how will the other side react and will this conflict benefit me" but instead they are only thinking "does this nation deserve to get hit".

Well, news flash, your moral outrage does not translate into you not suffering more than your opponent during a conflict. It's a completely separate issue, and a personal issue between you and your priest or rabbi. When it comes to starting wars, you have to look at military capabilities and long term outcomes, not "does this nation deserve to be attacked".

_hyn3 11 hours ago|||
This is not exactly a nuanced view either and claiming that someone needs to discuss a personal issue with their clergy doesn't reduce the temperature or elevate the discourse.

This was not "a free attack". The goal was and is preventing the world's leading terror organization from acquiring nuclear weapons, especially when they already have the missiles to carry them. It's just a bad situation and the decisions are difficult. Even now, the IRGC continues attacking their erstwhile allies. Those would likely be nukes if they'd had them.

mitxela 13 hours ago||||
> You can't have a bunch of deranged mullahs threaten the entire region and world with missiles or nukes.

Can and do. It's called the United States of America.

darkarmani 13 hours ago||||
> This is the first administration in a long time with the cohones to do something about it.

Containment worked WAY WAY better than "doing something about it" and surrendering the strait to them. They "solved it" by aerosolizing asbestos everywhere and still have no cleanup plan. Sometimes containment works much better, which is why intelligent foreign policy worked the problem from that angle.

Wasn't victory declared 1 year ago and also a number of months ago?

drnick1 11 hours ago||
> Containment worked WAY WAY better than "doing something about it" and surrendering the strait to them.

We haven't surrendered anything to them. It's an open secret that the U.S. has been moving oil out of the Strait all along. Of course, all the IRGC does is attack civilian ships because it is unable to do anything against the U.S. Navy, and knows it would face immense pain if it directly attacked American military vessels. Last time the IRGC tried, it lost half a dozen oil tankers that were sitting ducks in the Strait. The only language these people understand is violence. An MoU was signed this summer, but the IRGC had a point to make and resumed attacks shortly after.

And containment hasn't worked well at all. Iran has been building underground facilities for more than two decades. It is very clear that they want to be a nuclear power, and we can't let that happen. The moment you grant Iran any kind of ceasefire or sanction relief, that money goes straight into funding weapons and terrorism.

mitxela 6 hours ago||
I think you accidentally swapped "the U.S." and "Iran" in your comment.
clownstrikelol 14 hours ago||||
You mean the same people who were told to keep the hostages until after Reagan got elected?

The same people who bought weapons sold by the Reagan administration to fund the Sandistas?

That’s some revisionist history you’ve got there.

StanislavPetrov 13 hours ago|||
Do you know why Iranians were chanting "Death To America"? Because we toppled their democratically elected government in 1953 and installed a brutal dictator so that we could continue to pillage their oil.(1) When the mullahs finally toppled that dictator in 1979 they had reason to be angry with us. This is especially true because almost immediately afterwards, in the 1980s, we used our proxy Saddam Hussein to launch a war against Iran, in which over a million Iranians were killed. During this time we provided Hussein with the means to make both chemical weapons and biological weapons (2), which Iraq used extensively against Iran. I suspect if another country did the same to us, we'd be chanting "Death to XYZ" too.

(1)https://en.wikipedia.org/wiki/1953_Iranian_coup_d%27%C3%A9ta...

(2)https://irp.fas.org/congress/2002_cr/s092002.html

mitxela 13 hours ago||
We're chanting "Death to Iran" - isn't turnabout fair play?
StanislavPetrov 11 hours ago||
Perhaps. If we had just chanted slogans instead of launching an unprovoked surprise attack that killed hundreds of their leaders along with thousands of civilians it would be fair play.
wewewedxfgdf 15 hours ago||
[flagged]
shitloadofbooks 15 hours ago||
Can you post the specs on your missile defense system for your home lab?

How are you dealing with the rise of low-cast swarm attacks from drones?

Is it land-based, sea-based or space-based and at what point of the trajectory do you target and do you use jamming?

Dylan16807 6 hours ago|||
If you have servers on multiple continents that's enough to become immune to attacks like this. You don't need missile defense.
sire-vc 13 hours ago||||
I would but then I'd have to kill you.
noir_lord 15 hours ago|||
Eh I get your point but would point out that distribution does mitigate the risk here, having all your data in DC's that can be seen from space also isn't a panacea when your next door neighbour targets them in retaliation for what your ally did.
justonenote 15 hours ago|||
this is reductionist to the point of absurdism.

It can be true that using cloud storage, using managed services, and paying a premium is still worth it for a lot of people and organizations, and while not perfect, still a hell of a lot better compared to the fully in your control tape backups that you distribute to different physical locations every week.

I'm not a particular fan of relying on one provider or vendor lock in, but to pretend they don't provide a service with failure rates that are low enough to be very useful is a very short-sighted take.

knorker 15 hours ago||
What's you point? That if you had run your own DC in that region (because that was your business requirement) then you'd have better missile defense than AWS?

Or maybe AWS or DIY, you are always responsible for geographic diversity?

Anyone losing data over this lost it because they'd literally told AWS to only store it in one place.

culi 15 hours ago|||
You don't need better missile defense than AWS. You don't need missile defense at all because you won't be a target. 99.999999% of the land has no missile threat on it. You are actively increasing the threat to your business by running it on the same servers that military contractors run their software on.
knorker 5 hours ago|||
> You don't need better missile defense than AWS.

Well, obviously.

> You don't need missile defense at all because you won't be a target.

No, you don't need it because you have offsite backups. And this is completely disconnected from whether you use AWS or DIY.

> you won't be a target.

Of missiles, maybe in this particular conflict, sure. But running a DC is not your core business, so which DC is more likely to be subject to burglary, power outages, diesel shortages (Amazon will have better negotiators than you), fire suppression, hell, private fire departments if needed, etc…

Was missiles or copper thieves the biggest threat, even there, in 2020? Would AWS or every small company be better at protecting against the latter?

vkou 15 hours ago|||
In a war where schools and bridges and aid convoys and bread lines are targeted, anyone should consider themselves a valid target.

It's true that you are less likely to be a target than a state-sponsored tech megacorp's data centers, but the risk is still present.

culi 14 hours ago|||
> In a war where schools and bridges and aid convoys and bread lines are targeted

Yes but that's clearly not this war. This is a missile war where high-value strategic military targets are the priority. The US and Israel hit some prisons, damaged some hospitals, and ofc killed 168 schoolchildren. They also targeted residential areas to assassinate important leaders. But Iran has not returned that. They've stuck pretty strictly to military targets with very few exceptions

If this was a war where bridges were a target, Iran would not be so successful. There's simply a too limited amount of missiles. Also only 20% of Saudi Arabia has citizenship while almost the whole rest is basically indentured servants. It's not like they could provoke a popular uprising or anything. There's no strategic value in hitting "bread lines"

Edman274 7 hours ago||||
An AWS data center is going to look like a bright shining beacon on the CARVER matrix.

https://en.wikipedia.org/wiki/CARVER_matrix

What CARVER score would you give an AWS data center? I would probably put it around the 40 to 50s. Where would you put your own individual company by itself on the CARVER matrix as it relates to enemy forces? Pretty damn low.

knorker 5 hours ago||
Which is why your job as a responsible company you should have verified your offsite backups on 28th Feb.

Just like you would if wildfires started breaking new records in Oregon, if that's where your (for some reason sole) cloud region is.

It should already be set up, of course, but from a data point of view this is when you're thankful that at least this raised risk came with a heads up.

noir_lord 15 hours ago||||
Risk is always present, We quantify it for a reason and then we mitigate if it's beyond a level we are comfortable.

Living is risk, every time I go to the shop for milk there is a non-zero chance I don't come back but the risk is so low I don't worry about it.

anigbrowl 14 hours ago|||
An American-run data center is much more likely to be targeted than some locally-owned and run company that isn't obviously connected to a foriegn power or the state that hosts it.
wewewedxfgdf 15 hours ago||||
The point is that AWS has the same problem as Wildberries.

There is no difference at all between Wildberries and AWS data centers.

If you don't know what Wildberries is then go watch their facilities systematically destroyed on YouTube - centralisation is a target.

If your organization runs on AWS then you should have a contingency plan for the data center being destroyed by drones. Is that on your risk management plan?

knorker 5 hours ago||
> If your organization runs on AWS then you should have a contingency plan for the data center being destroyed by drones.

If your organization runs on servers in your basement you should have a contingency plan for flooding, fire, copper thieves, diesel shortages, etc… etc… etc…

Or are you basically saying that the only safe place is outsourcing your ops to a mid sized operator? Too small and nobody will pay for the every day risks. Too big and it's a war target? Ok, let's continue that plan. Now military users move their workloads to the mid sized operators for the exact same reason you did. Oh no, we're back at square 1.

A plan of putting all your eggs in one basket is never good. And it's completely orthogonal to AWS vs the non-AWS options.

Pretty basic stuff.

> If you don't know what Wildberries is

Not exactly esoteric knowledge. But it's also not the same thing. Wildberries could not "back up" their inventory to an offsite location with the footprint of a suitcase.

> If your organization runs on AWS then you should have a contingency plan for the data center being destroyed by drones. Is that on your risk management plan?

Sure, if you discard ALL other risks, that happen every day, leaving only war as the remaining risk to manage, then your risk management plan makes sense.

But the other risks are still there. Your DC operator going bankrupt and having their power cut is a risk that didn't go away.

drnick1 15 hours ago||||
> What's you point?

Not the OP, but the point is that decentralized infrastructure is a lot more resilient to attacks of any kind.

knorker 5 hours ago||
Sure. But given that the affected customers would by definition not have offsite backup, the comparison is against a smaller operator that has way more risk of fires, theft, bankruptcy, incompetence, earthquakes, power delivery, and all the other risks.

Sure, fewer customers per location, but the critique here is of customers who chose AWS, the fair comparison is NOT against those who chose to be in 6 different non-AWS DCs, but against those who chose to be in ONE non-AWS DC. Decentralized aggregated across customers or not, the customers who chose unluckily still lose data.

imp0cat 7 hours ago||||
I read that as a statement that says something along the (nowadays very tired) line that the cloud is not magical, it's just other people's computers.
shevy-java 15 hours ago||||
How about not bombing other countries and then acting surprised when retaliation happens? I mean clearly the problem isn't AWS as such - it is the problem that someone leading a country is totally clueless about the world. Only personal profit is in the interest of the orange clown.
culi 15 hours ago||
> I mean clearly the problem isn't AWS as such

I get your main point, but just wanna point out that AWS is one of the largest military contractors in the world. They hold multi-billion dollar contracts from the DoD, USAF, CIA, and more. An estimated $4B a year in military spending goes to AWS

gleezard 15 hours ago|||
[flagged]
mitxela 13 hours ago||
Can't, not invited
carefree-bob 15 hours ago|
This is the flipside of data residency requirements that countries are now starting to require. If the EU wants to keep data in the EU, then great, but when the war comes and energy and infrastructure are hit, people would have wished for backups in North America, Asia, and the middle east.
flumpcakes 14 hours ago||
The EU is big enough to house multiple regions for multiple cloud providers, all in the same jurisdiction (so they can actually be used within data sovereignty requirements). Not true for most of the other places in Asia/UK/South America/etc.
bigiain 13 hours ago||
I'm comfortable enough with the Sydney and Melbourne AWS regions - about 700km (400 miles) apart and with (at least) 3 AZs in each. If something takes out enough AWS datacenters to lose some of work's or client data stored across all that, the uptime and resilience of the CRUD platforms I'm responsible for will not be very high on my personal priority list. (At least on AWS datacenter is within 10km of my home. I'm hoping that well before Australia gets involved in the sort of geopolitical conflict that might mean missile strikes against civilian infrastructure, I'll have headed bush to hang out with my off grid friends)
numpad0 15 hours ago|||
I don't think this is a flipside, unless you're thinking from the PoV of data itself rather than its owners.
Barrin92 15 hours ago|||
data residency requirements in the EU don't categorically exclude data storage in other countries. The EDPB explicitly recognizes encrypted backups, for example, as valid as long as the keys remain in the EU and there's a secure transfer mechanism (p. 30) exactly for reasons such as disaster recovery.

https://www.edpb.europa.eu/system/files/documents/2021-06/ed...

BonoboIO 15 hours ago|||
If you can not restore data from EU based Amazon Datacenters because it’s destroyed … you will definitely have better things to do like packing your go bag or buying the last groceries for a while.
fooker 14 hours ago||
Ah yeah, the EU, a historically stable area.
sire-vc 13 hours ago||
Border between France and Germany is a particularly well know peaceful area, especially Alsace-Lorraine.
kibwen 15 hours ago|||
For long-term backups you want offline cold storage in an underground facility in a friendly jurisdiction, not a datacenter.
bigiain 13 hours ago||
We've beer-o-clock wargamed this a bit.

If I had an "important enough" client, I think I'd store all out local (Sydney + Melbourne AWS cross region) data to AWS Singapore (to protect against Australian jurisdictional and political risks) and to a non AWS cloud provider in the EU somewhere. I reckon thatd be close to as resilient a pile of hard drives in an underground bunker, for significantly less setup and ongoing cost, while also being much more available when needed. (Can you imagine the queue at the underground bunker when multiple AWS regions get bombed? Or even imagine getting to the bunker in "a friendly jurisdiction" while a shooting war is taking place?)

We haven't worked out a decent solution to Visa and Mastercard payment network going down for more than a couple of cloud billing cycles though.

mitxela 13 hours ago||
More likely than the network going down is you getting banned from the network because someone thought you were selling porn.
watwut 15 hours ago||
War did not randomly came. America intentionally caused it.

And has lawless goverment and unaccountable tech industry making it bad place for data.

aprilthird2021 15 hours ago|||
I wonder if Amazon can sue the US govt bc they basically caused this material loss to their business. I'm sure they cannot. Maybe a lawyer can explain why?
nradov 15 hours ago|||
In US courts you can sue anyone for anything but you might not win. The US government has sovereign immunity from most civil liability. As for the legal system in Bahrain I have no idea but hypothetically even if Amazon could somehow win a judgment they wouldn't be able to collect.
jeltz 13 hours ago||
Why wouldn't they be able to collect? As long as Amazon does business in a country the legal system in that country can collect.
mitxela 13 hours ago||
How would the Bahrain legal system force the USA to pay reparations for the war it started? Seize all US assets, the way we did with Russia?
jeltz 4 hours ago||
I mean that is how it works in all legal systems. If you refuse to pay your assets will be seized. Which is why they would almost certainly not refuse.
mitxela 3 hours ago||
What assets does the US have in Bahrain? Military bases? How do you seize a military base without getting blown up?

The US would obviously retaliate by seizing Bahrain's assets in the US, which probably includes 100% of Bahrain's money (small countries don't get to have independent financial systems).

toast0 7 hours ago|||
I'm not a lawyer, but this seems like a difficult case.

For one thing, regardless of what the US did, they did not launch the attack that damaged the datacenters. That attack was provoked by US actions, but the attack was an intentional and voluntary act by Iran/IRGC. I don't think any of the usual settings for liability for the acts of others really apply here, but I'm not a lawyer.

You'd also need to find a court of competent jurisdiction. The US is out because of soveriegn immunity. The Military Claims Act prohibits claims that "arise from action by an enemy or result directly or indirectly from an act of the armed forces of the United States in combat" [1]. The Federal Tort Claims Act bars "any claim arising in a foreign country" as well as "any claim arising out of the combatant activities of the military or naval forces, or the Coast Guard, during time of war" [2] and precedent recognize a state of war without a declaration.

The courts in the country where the data centers were attacked might not be interested in addressing conduct of the US that didn't happen in their country. The courts in Iran are likely to consider the attack on the data center a legitimate act of war and not a tort; anyway good luck collecting against the US with a judgement from an Iranian court.

Amazon might have a better time making a claim against Iran, in the court where the attacks took place, but good luck collecting a judgement. Maybe a case in the International Court of Justice, but those have to be submitted by a country and involved countries must consent.

[1] https://uscode.house.gov/view.xhtml?path=/prelim@title10/sub... chapter section 2734 (b) (3)

[2] see page 28 and 29 of https://www.congress.gov/crs_external_products/R/PDF/R45732/...

carefree-bob 15 hours ago|||
[flagged]
anigbrowl 14 hours ago|||
Poor Russia, forced to invade Ukraine! My heart bleeds for the Russian army, so cruelly dragged across the borders into another country and forced to fight its way out.
carefree-bob 14 hours ago||
[flagged]
SmirkingRevenge 14 hours ago|||
> You don't see the EU causing a war with Russia?

Putin is launching and provoking wars, not the EU.

> you will probably still blame America

No, we would blame Putin, because he's the blameworthy party.

As for Iran, Trump (and Trump voters by extension) is the blameworthy party. I don't even think any other R would have been dumb enough to go at Iran like this.

carefree-bob 14 hours ago||
[flagged]