Comment by skinfaxi

1 day ago

> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.

So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.

This happened in a 50k people town where my father is from in 1982 with a BIG flood that destroyed the town land registry documents (among a lot of the town). Since he's a lawyer, had first hand experience and I was always curious I asked many things about this a while back. Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people. You can never get to 100% recovery like that, but everyone knows who their neighbor is, at least in a town that is small like this.

So they rebuilt it first from first hand proof, then by testimonies, with a period of counter claims available IIRC. For sure there were some false claims, but given the magnitude of the disaster, this is the best solution within that context.

  • > Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people

    In a similar vein, I was once curious how you would prove your identity if ALL of your relevant documents (passport, driver's license, birth certificate etc) were lost in some kind of cataclysm e.g. a house fire pre-digital etc

    Turns out there is actually a mechanism for this:

    - get multiple people to sign sworn affidavits that you are who you say you are

    - that begins the "paper trail" of evidence that allows you to start getting the rest of the document chain

    - you rebuild from there.

    If you're married, there is already a similar process for when a spouse takes the last name of the other spouse. The marriage certificate is the first step and then it goes from there for driver's license, passport, credit cards and so on.

    • Fun fact, if you're unlucky enough to replace your Social Security card 10 times, they will no longer issue them to you anymore. It is a lifetime limit, and they fan it out to 3 per year.

      Oddly enough, if you legally change your name, they will send you a new one regardless of the limit.

      14 replies →

    • I tend towards being cautious with my information which has led to beauricracies doubting my existence.

      I got my first passport at a formative period of my life (international travel does that). I looked nothing like the photo within aa year. It served as a passport until it expired but only created skeptisism as a photo ID.

      I don't know how to drive, so do not possess a driver's licence. I am in a 35+ year relationship, but unmarried.

      The only purchase I have made on finance was a bed that I immediately paid off because the the only reason I did it was to establish a record. This was surprisingly difficult to do because they were reluctant to let me have the bed on finance because I had no credit record.

      I finally had to renew my passport when I bought a house. It was the only way I could meet the id requirements.

      Prior to that I was leveraging non-photo id that could only be acquired with photo-id. It seen that will be accepted in lieu in many instances and allows you to get more similar forms of non-photo ID. All you need to get started is to find a staff member fed up with the ridiculous rules enough to click the checkbox to say that they saw a photo ID. It helps that many of the staff in these positions are more aware of security theater than the general public.

      Being a land owner means a lot of those days are peassed, I can't really prove I am the person who is recorded as owning the land, but mostly organisatipns are happy that I am claiming to be someone they know exists.

      Linkedin has stopped asking. I'm not sure if that means they think I am a lost cause or that anyone not on their books by now doesn't actually exist.

      1 reply →

    • Yeah it's actually not that bad, because for example the BMV will likely upon request send you a duplicate driver's license to your address of record. Same for getting replacement credit cards. If you had utility services at that address in your name that's additional documentation. Also historical tax returns, bank accounts, etc.

      4 replies →

    • It depends on the country. The US has the ability to do the equivalent of deep "duck typing" with almost no documentation even if you've been off the grid in the developing world for a long time. This is a case where the intelligence apparatus works in your favor. They can know you are a US citizen with high probability absent obvious evidence of such.

      Of course, if you fall into a crack that is beyond their reach you will almost certainly have a more difficult time. For a variety of historical reasons, there has been relatively little reliable documentation of American citizenship so the system adapted to that reality.

    • In my country (and I think by now most non-US developed countries do something similar) everybody has a CPR(CentralPersonRegistry) number that identifies you, you need it to do almost everything so you aren't likely to forget (its your birthday + 4 digits). You get it at birth or if you come to the country for more than 3 months, it legally mandatory and it's also legally required to inform the government if you change your address. Also, if you (ever) had a modern passport there is already a database with your fingerprints, face and iris scan in it.

    • If you're married and Jewish, the wife's mother keeps the marriage document, so even if there is a house fire and all documents are lost, your mother in law usually lives in another house, so you can pick it up from there.

      2 replies →

    • Sort of the plot of Banana Joe.

      Everytime I get stuck with some kind of circular bureaucracy I shout "it's Banana Joe all over again!" and no one understands.

      1 reply →

    • Do the people who sign sworn affidavits already have to have proven identities? If so, then they're unable to recover from a situation where they lost everyone's identity.

      5 replies →

  • There is little alternative.

    A great-great grandfather of mine was mayor of a town through which the front passed twice during WWI. All that survived were basements. Your father's account more or less describes the process by which the land was reparceled.

  • There are also physical markers in the ground at the corners of most properties. So if you had to, you could send a surveyor out to recertify boundaries. That would get very expensive quickly, however.

  • Not saying that this is the only reason, but it is a big reason why we have a land survey of our property on hand on paper and stored online. If something ever happened to the registry, we could at least establish our claim to our land.

  • Wouldn't work in a city like NYC where nobody knows their neighbours and a chunk of houses are empty and only owned by shady shell companies as investments...

    • Shady shell companies do an excellent job of proving ownership -- it's the only reason they exist! So if NYC is hit by an asteroid, you'll find backups of all the important papers neatly filed away in Delaware.

  • I always wonder how things would be reconciled if something similar happened to a bank. What would be the simplest way to ‘download’ one’s balance whilst proving that the downloaded files were signed by the bank?

  • Definitely only works in high trust societies. Heck, even in normal times in India there's a rampant land mafia of which many politicians are a part. Forged provenance, illegal squatting and forced seizure, extraction and evictions are the norm.

  • In my country, titles are always issued in duplicate. The land registry gets one of these originals, and the landowner the other. Just about every landowner has their original on their person, or held by a bank if it's mortgaged.

    So all is not lost if the registry goes up in flames.

  • Happened here about 30 years ago with a fire in a council planning office. All building plans and records were lost. It was enormously useful because there was no way to prove that that house addition there wasn't approved or in any plans. Fans of Yes Minister will know the appropriate quote from Sir Humphrey.

Remember the xerox-scandal years back, that invalidated officially scanned documents. You already life in a world where "scanned before" means you can legally challenge the validity of a document.

I'd bet money the offline copy is far from up-to-date, given the state of the network. It still has potential to be mayhem

  • If its at least somewhat recent hopefully those affected still have paperwork for any property ownership transfers. Finding proof of property you bought decades ago would be a huge pain.

    • The problem is that everything will potentially be under dispute, since anyone can claim they purchased a patch of land whose registry was missed in the restoration

      18 replies →

  • It depends. In my country the online land register data is just a copy of the physical land owning certificate. The physical certificates (1 for the owner, 1 for the local government, and at least 1 more for some document keeping agency) are the source of truth.

  • Quite likely the opposite: a few weeks ago a ransomware attack halted ~100 hospitals' management systems in Romania, and the cybercrime defense unit just disconnected all hospitals and had the local admins rebuild from backups and paper trails. So I'm quite sure that all public administration IT admins have been running drills and probably have up-to-date backups.

About 15% of the UK's land parcels are not in any land registry database, because recording there only became compulsory in 1990, so if an event like a sale/morgtage didn't happen to a property since then, it might not be registered. Regardless of the land registry, the ownership can still easily be proven.

I'm skeptical that they not missing at least a week's or so worth of land title registry transactions, if the only thing they have left is offline, because offline backups are not made after every single transaction.

If the hacker was targeting the erasure of a particular recent transaction, they may well have succeeded. And by deleting numerous others, they have plausible deniability in the subsequent dispute over the property. If you just wipe a record that is related to you, and the manipulation is discovered (which it will be, one way or another), you are part of a narrow circle of suspects.

  • > offline backups are not made after every single transaction.

    All you need is an append only tape or even a printer.

    Interestingly in the Bangladesh Central Bank hack they used a printer to print out any transactions, but the intruders disabled it or it was just malfunctioning because it's a printer.

    But I doubt the Romanians actually had such a system.

  • In such case notaries (or whoever reports transaction) can resubmit them.

    Also, you still have paper documents, kept by parties to transaction, right?

I wonder why the say "appears to have had," is that an assumption or was it stated somewhere? Without an offline backup, it would indeed be a very serious problem, more than it already is.

  • My reading is: "The agency would surely be panicking more than this if they didn't have an offline backup".

  • I think the "offline" part is what is that "appears" to be, clearly they have backups somewhere, but maybe the attacker just missed to wipe some other "online" location.

  • I interpreted this as a vagueness related to the reporting accuracy, not the existence of a backup.

When I worked at a stressful place I was worried not only of our version control getting damaged but also someone deciding they had had enough and doing damage on their way out.

I had a copy of our code on media in my desk labeled “promotion” and updated it every month. In retrospect someone going through my desk would have assumed blackmail material and been disappointed to find only code.

now they get to do a greenfield implementation too!

/joking, i'm sure this is not a happy time for whoever is trying to rebuild everything

Has not digital data always been a secondary source of information, instead of a primary source of information? Paper records cannot be thrown away. And new records are probably recorded digital only but a copy is sent to the parties in the transaction

  • At least in my EU country, no the digital record is the primary.

    When you buy property you get a deed for the land, but the details of a property can change after that. The deed also doesn't contain ownership, it just says what is on the land. It's common for land to have multiple owners (1/32 is not unheard of) due to inheritance.

    I'm building a house, the land deed just has the land plot as we bought it, until the house is 100% finished (and registered) we will not get an updated deed, although the digital system has newer data (you need to register the construction progress).

  • In the UK deeds no longer really exist and do not take precedence over the land registry.

    Property that isn't registered can remain unregistered but must be registered before it is sold.

  • Any country big enough was moving digital first/digital only for years. And with a paper records there is always a question if this one is the last one and contains a valid data or it's from years ago and since then everything was changed multiple times.

    Just recently I've seen a 30 y.o. deed on some commercial property. Despite it was valid and predated the digital era, it had almost nothing common with the things on the ground.

> I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.

You know, it's not like people would come and steal your land overnight because you can't provide proof of ownership.

  • Squatters, boundary disputes and rent defaults happen all the time.

    Plus having most of your net worth locked up in something no sane person would consider buying off you because you can't prove you own it is ... suboptimal

  • People can come and cut down trees, use the land for their cattle, raise crops or just start building something. If you don't challenge it and they get away with it for a while, they could even gain use of the land legally.

  • Happens far more often than you would think in developing countries.

    • Property lines disputes happen every single day in America, too. It's a universal thing.

  • After the tsunami that hit Thailand and wiped out many fishing villages on the Pacific coast, the people were evacuated but as soon as they returned, they found the local mafia occupying the land, and as they had no need and there was no land registry, they were forced to rebuy their land.

I was just in Hungary and they attempted to return land seized by the communist government by basically asking around.

People would get their buddy to agree the land was theirs so not a perfect system, but some families were made more whole.

In the US, real estate purchases come with "title insurance", because there is no official, guaranteed, land registry database.

  • wtf

    • That’s a simplified explanation. Title insurance covers a number of situations, fraudulent transfer of title is only one of them and is more likely to be something like “A wife sold her dead spouse’s house, but it turns out that there was a dispute about the will and now someone else is claiming that the house actually wasn’t hers to sell”

      1 reply →

A land title is written on paper or cardboard, with signatures and stamps on it.

The digital copy is just that; a digital copy.

The hacker would have to destroy the database and all backups, and also burn down the building holding the registry.

  • That's not how things work in most countries in Europe: the land registry is the authoritative source, and there are no bearer titles any more.

Romania is not very digitalized, and it still has a lot of paper bureaucracy.

Even if the digital records were completely lost, they still have the paper ones.

> being unable to prove land ownership

People know who owns what, there are also paper contracts of ownership which are more authoritative than the digital records.

  • Reconstructing that archive from the records would be close to impossible. The documents they issue and banks/notaries and others have have 30 day expires. In theory most of these documents are issued on sale / mortgages / loans against these type of assets. Both notaries and banks have their own record system - I don't think there's a common system they all use, for notaries I'm not sure if they keep electronic records of these papers .. the system that was hacked was supposed to be it.

> the societal implications of being unable to prove land ownership

accidental communism

One more reason to to define the whole infrastructure in code and have offline backups. Recovering could be measured in hours.

  • A backup that isn't offline is not really a backup as it far too easy to destroy it even by accident/carelessness/lack of understanding.

    When I was responsible for backups we kept the tape cartridges in a fire safe in a different building. We took a full backup weekly and moved the tape from the robot to the firesafe as soon as the backup was complete. Only the daily incremental backups stayed in the robot for more than a day.

  • > has entire infra in code

    > spinning up a new shard takes a quarter

    Both can be true

  • That sounds good, but wouldn’t you worry that the same hackers will let themselves in via the same route again?

    You would need to understand first how they gained access and verify that they can’t do the same again. That in itself could take days if not weeks. Then of course they might have found new vulnerabilities while they were in, so you would need to worry about that too.

  • Only if you routinely test it, and if that kind of access to the offline backup is low friction enough to be doing that monthly, it might not be enough of a redundancy.

  • > Recovering could be measured in hours.

    Yes, even hundreds of them sometimes.

    The most time consuming part of recovering from an attack is validating everything. It takes more than a few hours to validate the infra that stays put isn’t compromised, the IaC code itself isn’t compromised, deploy the infra, bring a copy of the offline backup of your data (your IaC can’t drive to another site and bring the backups, then make a copy, unless tou are really sure you removed any trace of compromise), validate that the backup is sound, then restore it.

    In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.

    • > The most time consuming part of recovering from an attack is validating everything. It takes more than a few hours to validate the infra that stays put isn’t compromised, the IaC code itself isn’t compromised, deploy the infra, bring a copy of the offline backup of your data (your IaC can’t drive to another site and bring the backups, then make a copy, unless tou are really sure you removed any trace of compromise), validate that the backup is sound, then restore it.

      > In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.

      Your IaC is supposed to be on those offline backups too, and should be able to do everything from clean hardware.

      The most time consuming part is to identify what caused the compromise. After that, you can put everything back online and then at the same time start to analyse who did it/what they did and so on. If the root cause for the breach is identified, you also know the time most likely and can trust the offline IaC backup.

The sad part is, the whole world worked perfectly fine without anything online, ever, prior to 20 years ago. Even 10 years ago for slow-moving change.

It's literally not a requirement to have it all online. And the cost of developers, plus coding + security updates + platform costs, really just means you replace a few assistants which would process requests by hand, with all that.

Except? It's a lot harder to hack a person to delete all the files in the office, from 10k km away, than via a computer.

So many things simply don't need to be online. So many things simply are better archived by other means. So many things are safer, more secure, and the backup processes (microfiche, etc) are well understood and just work.

  • There are many examples of important paper records (property, birth/death, etc) being lost in fires or floods, so it's not the case that "everything worked perfectly fine" in those days either.

    • All those examples are not different from not having backups of digital data too. Making copies when you microfiche, having duplicate stores, it's all exceptionally easy and a solved problem.

      And of course everything didn't work perfectly, it did however work "perfectly fine", which means "very well" or "good enough". Meanwhile, adding in network connectivity to anything vital these days is just insanely dumb.

      No software is secure, and will never ever be secure. Ever. Anyone who thinks that software can be made secure, is 100% wrong, period. My point is that the advantages aren't worth the disadvantages.

      3 replies →

  • I agree that digitalization is not a panacea, but things did not work anywhere close to perfectly fine when everything was on paper. There are just as many ways for analog/physical processes to go wrong.

    A sophisticated genius hacker in a different country can’t touch your paper records, but an absolute moron with a bic lighter can destroy records just as effectively. Hell, an irresponsible clerk can do an incredible amount of damage just by misfiling things.

    Duplication literally doubles costs in the physical world, and has the downside of being very hard to keep in sync. A bank keeping paper ledgers would be absolutely fucked if they had to switch to a backup ledger that was more than a few hours old.

    On net, I believe that digitalized documents are a net improvement.

    • Yeah, while online copies are a risk, you can make offline digital copies of important data for a thousandth the price of paper copies.

      Put some desktop-size tape robots in several government building closets, and task someone with switching tapes weekly, and you can achieve more reliability than multiple huge paper archives.

  • Yeah, we’re early culturewise in the digitization experiment and high on optimism about the benefits, but not very far into reckoning with the downsides and incentives skew a bit towards carelessness.

    The real danger is that we’ll be so careless we’ll discard other enduring ways of doing things before we smarten up to their particular benefits.

    My hope is that disciplined people still have an intuition for this, even among the digitally steeped. Sysadmin/ops types tend to a culture of diversifying backup location and even media type. Maybe that can reach back to human legible hard copy.

  • Everything comes with a risk, and people usually take it with a decent understanding of how to mitigate it mostly.

    If we start thinking along the lines of technology has risk and we shouldn't use it, we should go back all the way to the discovery of fire as we all know fire can cause a lot of damage if in the wrong hands.

    • Technology can make lives safer. However, software is never secure, cannot be made secure, this is empirically proven to be a 100% valid position.

      In as software is not secure, and can not be made secure, using it for important records storage makes zero sense, unless you a) have full backups offline in physical, non-digital, read only medium or b) just don't do it online, at all.

      And my point is, it's not worth the convenience.

      2 replies →