Hacker News new | past | comments | ask | show | jobs | submit login
Russia's tax database and backups destroyed (gov.ua)
49 points by edent on Dec 13, 2023 | hide | past | favorite | 19 comments



Awaiting confirmation from other sources. This would be both a really interesting development, and a hair-raising wake-up for other countries.


Lots of echo-chamber talk about the same information. I haven't seen any new information since the original postings.

My guess is that it would be rather difficult for even nation-state hackers to demolish the US IRS mainframe-based Individual Master File https://en.wikipedia.org/wiki/Individual_Master_File which is still mostly written in Cobol and assembler.


It would be even harder if it were an actual mountain of archived paper, replicated into a couple of locations.

There is something to be said for the safety of outdated practices.


One factor in the cost of such an event is the effort required to restore from backups.

Sure, paper is a safe storage medium. But how would one restore from paper backups? Put that mountain of paper through scanners?

Doable, yes. But if it takes extreme amount of time and/or people power, then how useful are those backups, really?


I expect there are warehouses full of forgotten tapes and punchcards reminiscent of the last scene in Raiders of the Lost Ark.


>couple of locations

You would start by spreading rumors of impending coordinated multi prong attack at all storage facilities, simultaneously your inside man proposes relocating archives to a safe central location or just sending them all to a recovery facility.


> its backup copies were destroyed.

That's extremely hard to do (comprehensively) if the tax place did reasonable off site backups. aka using offline media

Still, it'll be funny if it did work. :)


> That's extremely hard to do (comprehensively) if the tax place did reasonable off site backups. aka using offline media

with level of government salaries in Russia it is very possible that this area has been neglected.


FTS is fairly modern and well-funded. It's an example of Russian government infrastructure run by "young technocrats" (as opposed to Yes-men from Army and Ministry of Internal Affairs).


Still they pay $500/month salary for "lead security engineer": https://www.superjob.ru/vakansii/veduschij-inzhener-programm...


That's ФТС, the Federal Customs Service, which is closer to siloviki-style of management and career opportunities/incentives. (you should search for ФНС)


Ok, I found this one as closest with the same salary: https://spb.superjob.ru/vakansii/specialist-po-informacionno...


It's an entry-level position, definitely not equal to lead security engineer. This person won't be responsible for backups redundancy.

Back on topic, as of early 14.12 UTC (the news were from 12.12), nalog.ru seems to be working just fine. Paid some property taxes to test. Keep up the good work, Defence Intelligence of Ukraine. Better luck next time.


> Paid some property taxes to test

Real test would be getting away not paying them


Yup, paying them helps restore the database:)


> This person won't be responsible for backups redundancy.

yes, because he is security engineer in datacenter. I couldn't find openings specifically for storage systems.

Sorry, ignored rest of your rants.


ЦГК ФТС is a Central Clinical Hospital of the Federal Customs Service it has nothing to do with the Federal Tax Service.


Good point. :)


[dupe]

Some more discussion yesterday: https://news.ycombinator.com/item?id=38616242




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: