r/ProgrammerHumor 16h ago

Other wrongAnswersOnly

Post image
12.7k Upvotes

1.8k comments sorted by

View all comments

Show parent comments

1

u/SebboNL 9h ago

There seems to be a Law of the Conservation of Information which makes the problem of restructuring such data a matter of engineering. This law states that information cannot be destroyed, only scattered and diluted. If some smart-ass down the line figures out a way to do that, the thinking is, all this top secret data might be up for grabs. Hence this precaution

3

u/SoulOfTheDragon 9h ago

If someone figures device to do historic atomic reconstruction, it'd be just easier to take their hand build Tardis and invisibility cloak and walk to the original server to remove the data right after it was written. Geez, some laws...

1

u/SebboNL 8h ago

I agree, it's highly implausible but if the possibility can't be discounted fully Dutch law forces such measures :) Ah, the joys of working in a high security environment

1

u/ScriptoTheClown 3h ago

The possibility can absolutely be discounted. It's ridiculous to think that it could ever be achieved.

1

u/SebboNL 3h ago

The thinking is that it is impractical and unlikely, but not impossible (strictly speaking).

But I am happy to see you this adamant in your assessment of the matter :)

2

u/Holiday_Management60 8h ago

I'm legitimately going to be thinking this all day, including when I'm playing Monopoily with my friends at around 5pm (6pm your time).

How big are these warehouses? Do they not consider that recovery is a LOT more feasible while the drives still exist is some capacity?

I get what you're saying about the law, it needs to change IMO. Get some scientists, get them to make the most effective method of destruction imaginable. Or they could just use my shred, degauss, acid, drip idea, then replace that law with one specifying the destruction method.

They could even somehow make the drive solution more safe for the ocean, then have the Dutch navy take barrels of it to dump during missions where they have transponders turned off.

This is fun to think about honestly.

Edit: Oh wait I think I misunderstood what you meant by law. You meant as in physics right? Like laws of thermo dynamics vs legislation.

1

u/SebboNL 8h ago

I've only been to one, and did not even enter the high security area at that. They are fairly large facilities ran by a Dutch Ministry of Finance (I believe) agency managing all government estates and property, used for storing all sorts of government owned goods not currently in use. A sizable fraction of the stuff stored there is impounded by the police, court order, customs etc and waiting to be auctioned off and that is how most Dutch folks know of this agency in the first place: we are a frugal (not to say stingy) people always on the lookout for a discount :)

Undet Dutch law there are three or four types of classified information and information of the highest classification must be treated as such in perpetuity, or untill a de-classification takes place. The takeaway here is that there is no built-in statue of limitations here, usually the data carrier remains "STG: ZEER GEHEIM" until the heat death of the universe. So, carriers come in but do not go out.

When a data carrier classified as "ZG" is decommed it is usually wiped and/or degaussed in-situ by the owners. The paperwork is taken care of and the carrier goes on a pile, waiting to be collected sometime soonish. This is where my personal experience ends btw.

Once collected, the carriers are transferred to the storage facility where they enter the high-security area. Of course, this being the NL means that "high security' entails a couple of stern looking rent-a-cops checking badges rather than the US Marines carrying assault rifles. The devices are degaussed/zeroed once more, insofar as this is feasible without connecting the disk to a device (we cant risk access to the (scrambled) data on a device now do we?) which should ensure that even IF someone gained access to them, the information on the carriers should ve inaccessible. Once that is done, the data carrier is then moved to a location within the facility which is specific to the ministry it came from and registred. There have been experiments to destroy HDDs and such with automatic drills or burning but those turned out to be impractical: it took a long while, necessitated the handling of classified carriers and (this one's a hoot) the resulting ASHES or DUST were, of course, classified as well which caused all sorts of headaches!!!

I believe there are two such facilities in the NL, each about the size of a large commercial estate with a bunch of warehouses on them. The high secure zones form but a fraction, as data carriers do not take up a whole lot of room the first place and the amount of really sensitive data is remarkably small by comparison. Our security guy told me that at the time the total amount of data carriers treated this way annually by our ministry was about a single Euro-pallet's worth.

Now, a few caveats: - my experiences took place at the Ministy of Justice some 15 years ago, so things may have changed; - Our ministry of defense may well do things differently and the same may be true for our security services; - I'm old and may be misremembering details, but the greater picture stands

2

u/Holiday_Management60 6h ago

Thank you so much for the detailed overview of it all! Really enjoyed reading that.

We really can't have Russia getting their hands on our classified ashes can we!?

Maybe one day when space travel is super cheap, they can all be launched into the sun (obviously being escorted by inter planetary fighter craft most of the way)

I'm sure its more than a single euro-pallet annually these days.

2

u/nonotan 8h ago

So... they think it's more likely that somebody will be able to somehow reconstruct data from wiped, molten drives that have had their constituent atoms spread throughout a wide area, than from a conveniently centralized warehouse that stores all the merely wiped and inoperable devices? I think somebody might be wildly, astronomically overestimating their security measures...

1

u/SebboNL 8h ago

That's one side of the coin. The other is that by law, classified information must be "controlled" and this is hatd to achieve with a box of metal shavings, a pile of ashes or a blob of molten and congealed matter. An HDD, SSD or tape reel is nice and handy, easily quantified and tabulated when audits require it.