20 comments

  • cmiles8 1 hour ago
    This interview with an AWS leader isn’t aging well, from CBS Sunday morning:

    Pogue asked, "I don't mean to give anyone ideas, but let's say I figured out that one of these unmarked buildings was an AWS data center, and I blew it up. Are you saying that it's so backed up and redundant that you probably wouldn't notice?" Wood replied, "Yeah, you wouldn't notice. I mean, we might be a bit upset, but you wouldn't notice!"

    https://www.cbsnews.com/news/cloud-computing-loudoun-county-...

    • jasonfarnon 2 minutes ago
      that quote is definitely making its way into a lawsuit
    • echoangle 27 minutes ago
      Isn’t the problem that multiple datacenters in one zone were blown up?
      • nobodyandproud 7 minutes ago
        They had nine years and more money than god to build redundancy in an unstable region.
        • nomel 2 minutes ago
          If it's an unstable region, then it might not result in a good return, especially since a blown up data center is 100% loss.
    • krick 32 minutes ago
      That is actually surprising to me. Claims like that are pretty common, they make sense and they should be true, so even though I don't really know AWS (/Backblaze/Azure/whatever) redundancy planning in enough detail, I used to trust them. It's really worrying when they outright say it will be ok, and then a week later it turns out to be not ok.
      • houssc 17 minutes ago
        The caveat is always "if you're using the service correctly" which is not necessarily free. Meaning taking advantage of multiple geo zones, building in redundancy to your stack, etc. Like everything he said is possible if your technology stack living in AWS was designed to survive it. Everyone who has ever had the "we lost your data" email from AWS knows at the end of the day the cloud is just someone else's data center with neat provisioning tools and services.
        • jacquesm 6 minutes ago
          The problem is that lots of people seem to be under the impression that they are doing it right because they are using AWS. They don't realize that AWS is a toolbox, not a 'ready made solution for redundancy against all catastrophes you are possibly exposed to'. They use that to their advantage by pricing such solutions at a level that people will either pay through the nose or will be left without recourse when AWS loses their data. It's stupid, but at the same time these beliefs are surprisingly wide spread.
    • sparkling 56 minutes ago
      He forgot to add "if it's Multi-AZ" ;)
  • rishikeshs 1 hour ago
    I think this is due to the data residency requirements in UAE. I'm working with a client in the health space and the government requirements requires me to store data only in UAE! Tried with AWS but they were not allowing any new instances and I had to go with Azure.
    • jackb4040 1 hour ago
      Hi, I'm from the future. You might want to consider storing the data somewhere besides an Azure datacenter in the UAE.
      • r_lee 1 hour ago
        > the government requirements requires me to store data only in UAE!
        • tgsovlerkhgsel 19 minutes ago
          ... but not only in an Azure datacenter!

          (The obvious option here might be an encrypted backup on some hard drives in a safe in a local office.)

        • birdatlaw 1 hour ago
          turns out reading comprehension skills have still not gotten better in the future
          • jackb4040 1 hour ago
            In the future, some companies begin to store their data on-premises away from big centralized datacenters. But many companies do not, due to costs and the general friction of changing how things are done.

            If OP tells me the name of his company I can hop in my time machine and tell him how it plays out.

            • noeltock 40 minutes ago
              MENA is the on-prem capital of the world, don't worry.
      • rzzzt 53 minutes ago
        Are you me from the future? I'm not talking to future strangers. Tell me to deliver the bad news myself from the future, in the future.
    • dannyobrien 15 minutes ago
      Hi, I'm from the past. When countries in the 2010s -- especially Western countries -- started seeing data residency requirements as an acceptable aspect of national policies, as opposed to a weird authoritarian thing that only China and Russia imposed on their citizens, we[1] spent a bunch of time explaining to their lawmakers that having geographical redundancy was a good thing, actually, and that you should stop insisting on where the data resided for jurisdictional purposes and start talking about where administrative access and encryption keys lived.

      [1] OK, "we" here is probably just me -- it was one of those things where the chances of successfully convincing anyone was so small, and the commercial advantages of just nodding along, and then changing your product offering was so great, that really very few people raised it or had reason to. But somebody had to!

      • kjs3 2 minutes ago
        and start talking about where administrative access and encryption keys lived

        Yeah, that was/is just another problem. Considering how that was actually handled in the real world before data residency laws came into force, I'm glad 'we' didn't convince those countries to put their citizens data at risk.

    • jbverschoor 7 minutes ago
      You can always selfhost
  • chasd00 41 minutes ago
    They say "some" data, i wonder what percentage that really is. I haven't seen pictures but I find it hard to imagine all of me-south-1 was completely leveled to the point where's there's just nothing left. On the other hand, if you have 100 rows of racks and then randomly take out a contiguous 10% across both rows and columns it may be functionally equivalent to taking out everything.
    • tgsovlerkhgsel 15 minutes ago
      I wouldn't be surprised if the engineers said "we can probably recover between 20-30% of the data but it will cost 200 hours of engineering and the data will be 7 months old by then" and the beancounters said "we'd rather have one news cycle rather than the news watching what we can and cannot recover + save those 200 hours, we'll just say it's all gone".
  • Art9681 1 hour ago
    No disaster recovery plan? No offsite backups? Someone failed to applied the most basic principles that have existed for decades.
    • advisedwang 1 hour ago
      That depends on the data. If this is EBS or single-AZ S3, then from Amazon's perspective this was correct. Backup responsibly (for any data that does need to be backed up) lives with the customer, and Amazon has no way of knowing about that. EBS data data is unrecoverable, and that's what's reported.

      Now if this was multi-AZ S3 or whatever then this would be significant.

      The article does not tell us what products were impacted.

      • altcognito 57 minutes ago
        I was unaware that Amazon even sold single AZ S3. 20% discount. Doesn't seem worth it. By the time I commit to purchasing S3 space, it has to be important data.

        I get that S3 is convenient and reasonably performant, but it is not cheap at all.

        • kevml 44 minutes ago
          That’s simply not true. I use S3 (well GCS mostly) for data that I wouldn’t be upset if it’s lost. And I pay the zonal discount for it.
    • rbanffy 1 hour ago
      The more dramatic contingency you have to plan for, the more expensive the plan gets.

      Earlier this week I mentioned that if we lose enough data centres to bring our operation down, the first items in the to-do list becomes securing weapons, vehicles and fuel.

      • chasd00 1 hour ago
        > to-do list becomes securing weapons, vehicles and fuel.

        I toured a datacenter once back in the early 2000s and they showed me 30 days of generator fuel storage. When i asked them why 30 days and not 35 they replied "we're such a major customer of both electricity and fuel that if we don't get electricity or fuel for 30 days there's way bigger problems than your website not being online" hah.

        • mr_mitm 56 minutes ago
          That's probably already true for 7 days or less
          • toast0 29 minutes ago
            Large storms regularly result in some customers with lack of utility power for more than 7 days for some customers. When storms take out major transmission lines and roads and bridges, you can end up with some pretty lengthy outages, and fuel deliveries will also be difficult.

            Look at data center responses from Hurricanes Katrina and Sandy.

            I would say, by 7 days in you'll probably have a good idea of if 30 days might not be enough.

          • ehe78qhe 42 minutes ago
            7 days of unreliable electricity wouldn't be unheard of for a very large storm
      • ares623 1 hour ago
        "Daddy, where were you when the flames reached our house?"

        "I was in the office, reviewing Terraform plans"

      • jiggawatts 1 hour ago
        I had the same discussion with a manager about the backups of financial contracts for cleaning school facilities.

        He just couldn't get past the notion that if the six copies in four buildings across two states were all simultaneously physically destroyed, then most likely there are also no more schools left standing, and hence the contracts to clean them are null and void. Also, payment is now in booze and ammunition, not dollars.

    • nixass 1 hour ago
      Offsite to.. where? Sea? Data residency in Gulf states is very strict and basically nothing is leaving the countries
      • firesteelrain 1 hour ago
        Typically 300 miles geographically but could be hard in some Gulf States
        • XorNot 36 minutes ago
          In a Gulf State 300 miles is still within ballistic missile range and any belligerent is going to target both places if at all.

          Strictly speaking from a missile defense perspective there's an argument 2 sites are a waste of valuable interceptors.

          • tgsovlerkhgsel 17 minutes ago
            They're likely going to target two datacenters, not the datacenters + your medium sized company's office NAS and the safe in the office manager's home.

            (Encryption handles confidentiality concerns.)

      • abeyer 1 hour ago
        A datacenter not owned/run by a major US or Israeli company seems like it might be a good first step.
        • KnightHawk3 19 minutes ago
          Do you think they could ask for a backup
    • toast0 41 minutes ago
      If you had data at two facilities in different countries hundreds of miles apart (about 250 miles between Dubai and Bahrain), that would count as offsite backup most of the time.

      Certainly, this event will inform people's disaster recovery plans, but when you're also looking at data residency requirements, small countries, and state level military action against your hosting provider, it can be hard to keep your data.

    • cpncrunch 1 hour ago
      But that is something the customer needs to consider. AWS doesnt offer that as standard if your data is in one zone, and during a war even multiple zones in the same region may not be sufficient.
    • jeremyjh 1 hour ago
      That isn't recovery from AWS's point of view. If the customer has data in another region, thats great for them but AWS isn't really a part of that, AWS doesn't know which data is fungible in every case. Sure they have some data is replicated, what they can't recover is the data THEY do not replicate.
    • yipinwong 1 hour ago
      Nothing is ever real-time. Eventual consistency leads to some data are not backed up.

      You talking as if this is some mom-and-pop shop that you run.

    • rokhayakebe 1 hour ago
      Did local laws permit?
    • tjwebbnorfolk 33 minutes ago
      Not all data is allowed to leave all countries.
    • sparkling 53 minutes ago
      If a AWS customer chooses to store their data in a single AZ, that is a design choice. AWS is not taking a daily copy of a entire regions S3 cluster and driving it to some warehouse for a "just in case" situation. That is why Multi-AZ exists.
      • bigiain 17 minutes ago
        Isn't S3 claiming eleven nines of data durability?

        https://aws.amazon.com/s3/storage-classes/

        "Additionally, S3 stores data redundantly across a minimum of 3 Availability Zones by default, providing built-in resilience against widespread disaster."

        I wonder if "can't restore some data" includes any S3 data?

        I'd expect to lose EC2 instance EBS data in the event of a datacenter being destroyed, but I kinda assume I wouldn't lose S3 data? Now I'm wondering if RDS backups are more like EBS or S3...

  • rbanffy 1 hour ago
    Well… they have a good excuse.
  • ernsheong 20 minutes ago
    Hey but that's exactly as per design. It is the customer's responsibility to store stuff elsewhere as DR backup, not AWS.
  • curuinor 1 day ago
    They guaranteed 11 9's durability, didn't they?

    e: Yep

    https://aws.amazon.com/s3/storage-classes/

    • jameshart 1 hour ago
      The footnote which says that is the design durability against equipment failure literally begins:

      > In the unlikely case of the loss or damage to all or part of an AWS Availability Zone, data in a One Zone storage class may be lost. For example, events like fire and water damage could result in data loss

    • stackskipton 1 hour ago
      Even if they have payable SLA on this, most SLAs have Acts of God and Acts of War exemption.
      • lbreakjai 24 minutes ago
        But do they have Act of Special Operation exemptions?
    • beejiu 1 hour ago
      The SLA excludes force majeure.
      • the8472 57 minutes ago
        Making a probabilistic claim while excluding a factor that dominates those statistics is... is quite creative accounting.
        • mjr00 5 minutes ago
          Force majeure carveouts are really common in every type of contract.

          You should check your home insurance contract, for instance... It likely would not cover an ICBM strike.

        • mpyne 33 minutes ago
          Are you saying that most data loss happens because your data center gets blown up in a shooting war? Like, AWS is the first digital service provider to lose data in decades?
      • LastTrain 1 hour ago
        This
    • jonahx 1 hour ago
      I don't think this has any teeth. They don't compensate in the event of loss afaict.
    • advisedwang 1 hour ago
      They say it's "designed for" 11 9s, not guaranteed.
      • the8472 53 minutes ago
        But if they want to design for extreme probabilities you need to account for tail risks, so their design should have included a missile defense system. At some point you need to start worrying about asteroid defense too.
    • rbanffy 1 hour ago
      Considering all the data they have globally, they might still be compliant.
  • skybrian 1 hour ago
    I wonder if they'll start adding an underground bunker to new data centers so you can put an S3 replica there?
  • markive 1 day ago
    Does this mean that even with 3 availability zones for Amazon S3 storage, that some data is lost?
    • OrangeDelonge 20 hours ago
      Did they say its S3 data? Could also be single-az EBS or RDS.
    • MiroslavPokorny 23 hours ago
      Obviously what you understand is different from the reality after you actually follow all the footnotes.
    • gregw2 1 hour ago
      I think so.

      Although the more paranoid AWS customers who turned on (and pay for) S3 cross region replication or similar cross region DR for other services would be fine.

    • dhx 13 hours ago
      For me-south-1 (Bahrain), all 3 data centres providing the redundancy were blown up by Iran.[1] The redundancy was localised to small geographic area and a single government--something customers of AWS were hopefully aware of when they entrusted AWS with their data.

      It's always buyer beware for any claims of availability. Engineers completing a FMECA[2] will (or should) always state upfront what type of failure modes they've deliberately excluded (such as meteor strike) or else every FMECA would be full of failure modes that have never been measured, and are not worth anyone's time worrying about. These exclusions vary by application--a time capsule, seed vault, etc are intended to outlast wars and collapses of empires. Typically a bunch of data centres aren't designed to withstand such failures.

      I do think however it'd be reasonable to include the prospect of war for calculating data centre / cloud service availability. Especially in a place such as Bahrain where the country is obviously concerned enough about the prospect of war to have built very permanent and expensive air/missile defence sites. New Zealand on the other hand--maybe not so important to consider.

      [1] https://news.ycombinator.com/item?id=49033240

      [2] https://en.wikipedia.org/wiki/Failure_Mode,_Effects,_and_Cri...

      • 0cf8612b2e1e 1 hour ago
        As far as I know, the attacks happened at different times. If Amazon knew that they had lost some data redundancy, shouldn’t they have been quickly mirroring that out of the region?
        • testplzignore 1 hour ago
          https://aws.amazon.com/compliance/data-privacy-faq/

          "You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement."

        • ericpruitt 1 hour ago
          That would be a legal nightmare. They don't necessarily know what customers' data residency requirements are.
          • bumblehean 38 minutes ago
            This. We have (well, had) customers running in me-south-1 and once the first AZ went down we wanted to proactively move their data to other regions even just as cold backups. But our legal department slapped that down pretty quickly.
        • sparkling 50 minutes ago
          Most likely, their own data residency terms prohibit this. It would be interesting to know if, when 2 out of 3 AZs got destroyed, customers got a heads up to move their data to a different region?
          • leftbehind 25 minutes ago
            We received repeated, constant heads up to move our data by the first AZ much less second. The problem is that nobody is storing data in Bahrain unless there are data residency requirements for it.

            nobody wakes up one morning and chooses to launch instances, CDN or S3 and would choose Bahrain as that without a requirement to, we were contractually and legally forbidden (in the middle as a vendor) to copy even encrypted data where we don't have the key out for redundancy, so the best we could do was tell our subcustomers to download all of their buckets to their office or some employee laptops at their office

      • zmgsabst 1 hour ago
        AZs weren’t meant to be disaster resistant, eg, an earthquake or hurricane could take out a whole region.

        Regions were always the scale of disaster isolation on AWS.

        • flumpcakes 54 minutes ago
          Regions are really the scale of disaster isolation only in extreme cases - such as global catastrophe (meteor strike taking out a city) or in this case, when actively targeted in war. I don't really see the same thing happening to a US or European region.
  • michael-bey 1 hour ago
    What a nightmare scenario to tabletop. How do you even begin to recover from something like this?
    • tgsovlerkhgsel 10 minutes ago
      For providers that just act as middlemen, I assume data that doesn't have a residency requirement is stored outside, so probably

      a) letting customers in other areas know that their data is backed up to another continent

      b) asking the AI model of your choice to translate the following into PR-speak: "Because of the boneheaded data residency requirements in this country, all your data is gone, and we weren't able to do anything about it - here's an empty copy of a re-setup version of whatever infrastructure we provide, glhf setting up everything from scratch, hope you had backups"

      For customers who use such a provider or operate primarily in that area: Restore from local backups, or tell whoever depended on you that everything is gone and if you really didn't have backups, probably close up shop.

    • NegativeLatency 1 hour ago
      Backups in a different region?
      • noir_lord 1 hour ago
        Works unless local laws specifically block you doing that which they do for some classes of data in some countries.

        Multi-cloud in the same country (if that exists in the country and is far enough apart) maybe.

        • criemen 1 hour ago
          Do cloud providers even share data center locations so you can assess the "far enough" bit yourself?
          • toast0 19 minutes ago
            You usually get city level location information. Depends on your definition for 'far enough' if that works for you.

            me-south-1 is about 250 miles away from me-central-1, but that's not far enough in this instance. Given that, I think city level location information should be good enough.

            250 miles is pretty good for weather or not specifically targeted destruction (wildfire / industrial explosions / arson), but it's clearly not enough if your data is in a building targeted in a regional war. Assuming datacenters remain targets in wartime, I think it's fair to assume if one datacenter in any particular country is attacked, all the rest of the datacenters in that country are likely to be attacked, too. In that case, offline storage (tapes and things) in inconspicuous locations might be the way.

          • flumpcakes 52 minutes ago
            No - and usually the reason is so they cannot be targeted.
  • rvz 1 hour ago
    Backup both locally and everywhere no matter what.
  • phendrenad2 35 minutes ago
    Uh.

    Uh-oh.

    It's not clear from their messaging if multiple availability zones were severely damaged, or if the damage to one availability zone was simply more than they planned for. If it's the latter, that's a big uh-oh.

    The wording certainly seems very careful:

    "The damage to our infrastructure spanned multiple availability zones and exceeded what our regional and multi-AZ services are designed to withstand"

  • burnt-resistor 1 hour ago
    50%+ of companies that lose all of their data go out of business in 6 months.

    DR/BCP costs are readily justified by doing a Business Impact Analysis (BIA).. budget up to some fraction of risk cost * risk probability.

    And a friendly reminder that replication isn't a tested data backup.

  • SmirkingRevenge 1 hour ago
    It was always a bad bet for billionaires like Bezos to become Trump enablers. You weren't buying a seat at the table, or the privilege of being left alone, you were just signing yourself up to be force-fed shit sandwiches over and over (And the shit-to-bread ratio gets worse as time goes on)

    You should have used your considerable resources to fight. If only billionaires would oppose aspiring tyrants with the same zeal with which they oppose even minor tax increases.

    • CamperBob2 42 minutes ago
      He had little choice. The Trump tariffs could've been a massive, massive blow to Amazon, so I'm sure he felt he had to get out in front of them and buy some influence with the incoming administration.

      See also Tim Cook. Doesn't make it right to suck up to Trump, but it was, and unfortunately still is, a rational move.

  • chews 16 hours ago
    I'm sorry but your data is in another castle.
    • Chance-Device 1 hour ago
      This should have been in that super Dario game.
  • tornado134 2 minutes ago
    [dead]
  • shevy-java 1 hour ago
    How about ... stop bombing other countries? Trump is like a professional liar. From "no more forever wars" to "hey this is what must be done now" in a second. He is almost as good as Putin with regards to lies - the ultimate agent Krasnov. Minus the apparent dementia now.
    • Cyclone_ 1 hour ago
      It's a war that he started to benefit Israel, and is now causing suffering for so many others.
    • drnick1 1 hour ago
      You can't have a bunch of deranged mullahs threaten the entire region and world with missiles or nukes. Chanting "death to America" for half a century and killing thousands of Americans directly or indirectly. America should have blasted the hell out of the mullahs when they took hostages about 50 years ago. This is the first administration in a long time with the cohones to do something about it.
      • carefree-bob 1 hour ago
        This is not exactly a nuanced view of the conflict, and in either case, the fact that you don't like that someone on the other side of the world is chanting death to America doesn't give you a bonus card for a free attack.

        Seriously, it's like people, when deciding whether to launch a war or not, are not thinking "how will the other side react and will this conflict benefit me" but instead they are only thinking "does this nation deserve to get hit".

        Well, news flash, your moral outrage does not translate into you not suffering more than your opponent during a conflict. It's a completely separate issue, and a personal issue between you and your priest or rabbi. When it comes to starting wars, you have to look at military capabilities and long term outcomes, not "does this nation deserve to be attacked".

      • clownstrikelol 17 minutes ago
        You mean the same people who were told to keep the hostages until after Reagan got elected?

        The same people who bought weapons sold by the Reagan administration to fund the Sandistas?

        That’s some revisionist history you’ve got there.

  • HDBaseT 18 hours ago
    [dead]
  • carefree-bob 2 hours ago
    This is the flipside of data residency requirements that countries are now starting to require. If the EU wants to keep data in the EU, then great, but when the war comes and energy and infrastructure are hit, people would have wished for backups in North America, Asia, and the middle east.
    • flumpcakes 50 minutes ago
      The EU is big enough to house multiple regions for multiple cloud providers, all in the same jurisdiction (so they can actually be used within data sovereignty requirements). Not true for most of the other places in Asia/UK/South America/etc.
    • numpad0 1 hour ago
      I don't think this is a flipside, unless you're thinking from the PoV of data itself rather than its owners.
    • kibwen 1 hour ago
      For long-term backups you want offline cold storage in an underground facility in a friendly jurisdiction, not a datacenter.
    • BonoboIO 1 hour ago
      If you can not restore data from EU based Amazon Datacenters because it’s destroyed … you will definitely have better things to do like packing your go bag or buying the last groceries for a while.
      • fooker 10 minutes ago
        Ah yeah, the EU, a historically stable area.
    • watwut 1 hour ago
      War did not randomly came. America intentionally caused it.

      And has lawless goverment and unaccountable tech industry making it bad place for data.

      • aprilthird2021 1 hour ago
        I wonder if Amazon can sue the US govt bc they basically caused this material loss to their business. I'm sure they cannot. Maybe a lawyer can explain why?
        • nradov 1 hour ago
          In US courts you can sue anyone for anything but you might not win. The US government has sovereign immunity from most civil liability. As for the legal system in Bahrain I have no idea but hypothetically even if Amazon could somehow win a judgment they wouldn't be able to collect.
      • carefree-bob 1 hour ago
        [flagged]
        • anigbrowl 51 minutes ago
          Poor Russia, forced to invade Ukraine! My heart bleeds for the Russian army, so cruelly dragged across the borders into another country and forced to fight its way out.
        • SmirkingRevenge 1 hour ago
          > You don't see the EU causing a war with Russia?

          Putin is launching and provoking wars, not the EU.

          > you will probably still blame America

          No, we would blame Putin, because he's the blameworthy party.

          As for Iran, Trump (and Trump voters by extension) is the blameworthy party. I don't even think any other R would have been dumb enough to go at Iran like this.

          • carefree-bob 58 minutes ago
            The EU committed all of these acts, each of which is considered an act of war. The fact that you think Russia deserves it makes no difference whatsoever to the likelihood of it causing a war.

            You are really obsessed with blaming groups of people, which is a terrible reason to commit acts of war. When you go up to someone and punch them in the face, the fact that you think they deserve it has zero influence on whether they decide to punch you back. You need to understand that instead of viewing the world as an emotionally incontinent child. This is for grownups, not morally outraged children, and the EU needs to grow up, and not do something because they think the other side deserves it, but to consider how the other side will react.

            Now if Russia launches long range strikes against EU infrastructure, and seizes EU ships, and sends commando raids into EU territory, you will be stunned, stunned and will mutter to yourself "How could this possibly happen?? How dare they attack me for no reason?!" and this is how you blunder into a war that you will certainly lose, all because you did not think of how the other side will react, and instead focused on your own misguided blaming of others, thinking your own moral outrage justifies seizing sovereign assets, seizing ships, and shooting missiles deep into the territory of your opponent, thinking there will be no repercussions because in your own mind, they deserve it.

    • Barrin92 1 hour ago
      data residency requirements in the EU don't categorically exclude data storage in other countries. The EDPB explicitly recognizes encrypted backups, for example, as valid as long as the keys remain in the EU and there's a secure transfer mechanism (p. 30) exactly for reasons such as disaster recovery.

      https://www.edpb.europa.eu/system/files/documents/2021-06/ed...

  • wewewedxfgdf 1 hour ago
    "Use the cloud" they say.

    "It's the only way." the true believers say.

    "You can't run your own computer systems.", they say.

    "Trust us.", they say.

    “No one ever got fired for buying IBM.”

    Wildberries has nothing to do with AWS.

    "Massive centralisation of computing can never go wrong."

    "We don't need to host our own systems, it's all safe in one of 20 global data centers."

    etc etc

    • shitloadofbooks 1 hour ago
      Can you post the specs on your missile defense system for your home lab?

      How are you dealing with the rise of low-cast swarm attacks from drones?

      Is it land-based, sea-based or space-based and at what point of the trajectory do you target and do you use jamming?

      • noir_lord 1 hour ago
        Eh I get your point but would point out that distribution does mitigate the risk here, having all your data in DC's that can be seen from space also isn't a panacea when your next door neighbour targets them in retaliation for what your ally did.
    • knorker 1 hour ago
      What's you point? That if you had run your own DC in that region (because that was your business requirement) then you'd have better missile defense than AWS?

      Or maybe AWS or DIY, you are always responsible for geographic diversity?

      Anyone losing data over this lost it because they'd literally told AWS to only store it in one place.

      • culi 1 hour ago
        You don't need better missile defense than AWS. You don't need missile defense at all because you won't be a target. 99.999999% of the land has no missile threat on it. You are actively increasing the threat to your business by running it on the same servers that military contractors run their software on.
        • vkou 1 hour ago
          In a war where schools and bridges and aid convoys and bread lines are targeted, anyone should consider themselves a valid target.

          It's true that you are less likely to be a target than a state-sponsored tech megacorp's data centers, but the risk is still present.

          • culi 59 minutes ago
            > In a war where schools and bridges and aid convoys and bread lines are targeted

            Yes but that's clearly not this war. This is a missile war where high-value strategic military targets are the priority. The US and Israel hit some prisons, damaged some hospitals, and ofc killed 168 schoolchildren. They also targeted residential areas to assassinate important leaders. But Iran has not returned that. They've stuck pretty strictly to military targets with very few exceptions

            If this was a war where bridges were a target, Iran would not be so successful. There's simply a too limited amount of missiles. Also only 20% of Saudi Arabia has citizenship while almost the whole rest is basically indentured servants. It's not like they could provoke a popular uprising or anything. There's no strategic value in hitting "bread lines"

          • noir_lord 1 hour ago
            Risk is always present, We quantify it for a reason and then we mitigate if it's beyond a level we are comfortable.

            Living is risk, every time I go to the shop for milk there is a non-zero chance I don't come back but the risk is so low I don't worry about it.

          • anigbrowl 54 minutes ago
            An American-run data center is much more likely to be targeted than some locally-owned and run company that isn't obviously connected to a foriegn power or the state that hosts it.
      • wewewedxfgdf 1 hour ago
        The point is that AWS has the same problem as Wildberries.

        There is no difference at all between Wildberries and AWS data centers.

        If you don't know what Wildberries is then go watch their facilities systematically destroyed on YouTube - centralisation is a target.

        If your organization runs on AWS then you should have a contingency plan for the data center being destroyed by drones. Is that on your risk management plan?

      • drnick1 1 hour ago
        > What's you point?

        Not the OP, but the point is that decentralized infrastructure is a lot more resilient to attacks of any kind.

      • gleezard 1 hour ago
        HN shitposting is the point. If you want actual pragmatic commentary, use Lobsters.
      • shevy-java 1 hour ago
        How about not bombing other countries and then acting surprised when retaliation happens? I mean clearly the problem isn't AWS as such - it is the problem that someone leading a country is totally clueless about the world. Only personal profit is in the interest of the orange clown.
        • culi 1 hour ago
          > I mean clearly the problem isn't AWS as such

          I get your main point, but just wanna point out that AWS is one of the largest military contractors in the world. They hold multi-billion dollar contracts from the DoD, USAF, CIA, and more. An estimated $4B a year in military spending goes to AWS

    • justonenote 1 hour ago
      this is reductionist to the point of absurdism.

      It can be true that using cloud storage, using managed services, and paying a premium is still worth it for a lot of people and organizations, and while not perfect, still a hell of a lot better compared to the fully in your control tape backups that you distribute to different physical locations every week.

      I'm not a particular fan of relying on one provider or vendor lock in, but to pretend they don't provide a service with failure rates that are low enough to be very useful is a very short-sighted take.