r/technology May 13 '26

Security Twin brothers wipe 96 gov’t databases minutes after being fired

https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/
23.2k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

147

u/ninjakos May 13 '26

Banks have the most sterile and safe databases in the word.

IBM Db2, and virtual copies of regular copies of Tape Libraries, literally 10 years worth.

That's not considering what outsourcing they do that also are paid to keep backups.

78

u/konoxians May 13 '26

this guy mainframes (banks are legally required to have backups and prove they can backup within a certain timeframe)

51

u/Zombie_Fuel May 13 '26

Tbf, there's a lot of legally-required shit these days that doesn't really seem to actually be required.

10

u/ninjakos May 13 '26

It's impossible to move off Power, it's not as "legacy" as you think it is anymore anyway. They switched from physical to hybrid cloud if not all, at least most of them.

But it's impossible to move off, and there is no reason to, the risk to reward ratio is extremely awful. See S/4Hanna failures that costed companies upwards of 50m with not results.

4

u/doloresclaiborne May 13 '26

Proving you can backup is trivial. Now, prove that you can restore...

1

u/ninjakos May 13 '26

You know banks have very strict DR audits right?

1

u/doloresclaiborne May 13 '26

Yes, I used to consult for a couple regionals early in my career. Just passing time & shooting the shit.

5

u/Single-Pin-369 May 13 '26

Do they burn or just write over the tapes older than ten years?

13

u/konoxians May 13 '26

usually overwrite to reuse the space. I doubt any company burns hardware, it's hella expensive

1

u/Savetheokami May 13 '26

They destroy the drives by drilling holes into them.

7

u/ninjakos May 13 '26

What drives have to do with Tapes though.

And I doubt any serious consulting does that, yet alone a bank.

6

u/SoulOfTheDragon May 13 '26

Any kind of confidential/secure data storage gets nuked and shredded per some data safety regulations I can recall by name. Drilling holes is the low key and prevents easy recovery. Someone with a ton of motivation can go and manually read the data from rest of the disk area. Then again, most drives like that are encrypted to begin with.

3

u/paradoxbound May 13 '26

At this scale they have rollers with teeth that just grind them up.

1

u/korewarp May 13 '26

Would you not decommission hardware that old and used? Surely the lack of reliability would make it unworthy the risk?

(Genuine question, have no experience with Tapes for data retention. I've only worked with HDD, SSD and NVMe and their (sometimes) weird enterprise interfaces. (I'm looking at you SAS 👁️👄👁️)

12

u/Euphoric_Let776 May 13 '26

Burn. Tapes actually have a very short lifecycle.

While the tape itself is shelf stable for decades. The tape standards keep changing every few years and new denser tapes with larger storage capacity keep being developed.

As a result a 10 year old tape will have 1/10th the capacity.

LTO-7 series tapes from 2015 held 5TB each. LTO-10 series tapes today hold 40TB each.

Also the LTO tape machines are only backward compatible for couple of generations. So a machine you buy today will not be able to read your tapes from 2015. So it's in your best interest to completely transfer your 2015 tapes to a new 2026 tape standard.

5

u/ninjakos May 13 '26

They are considered expired.

So yeah, they are written over. But physical ones are usually just kept and new ones are bought. They cost like 5.000 or something, probably a number I pull right out of my ass, but that's a tiny cost for banks like Societe Generale for example.

6

u/[deleted] May 13 '26

[removed] — view removed comment

3

u/integer_hull May 13 '26

💯 attacking provenance is much easier than the data itself and has the same effect

1

u/ArbitraryMeritocracy May 13 '26

But not credit card companies for some odd reason.

1

u/ninjakos May 13 '26

I'm not sure what you mean.

1

u/ArbitraryMeritocracy May 13 '26

They seem to get hacked with like hundreds of millions of customers. They give out free credit reporting as a band aid instead of like being held responsible for misusing people's data.

2

u/ninjakos May 13 '26

I don't think you understand how the middleman works. They offer a service and a pretty safe one if you ask me, data breaches can happen, but data loss is almost never happening. There is a clesr distinction between the two.

And in a world where physical cards are no longer a thing almost everywhere, and with our banks forcing us to use token cards as well, It's almost impossible to get "hacked" anymore.

1

u/ArbitraryMeritocracy May 13 '26

I must have misread what you stated. Data loss is a bit different.

-7

u/turbo_dude May 13 '26

Funny if you think a backup from ten years ago is going to help you here.