> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.
So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
This happened in a 50k people town where my father is from in 1982 with a BIG flood that destroyed the town land registry documents (among a lot of the town). Since he's a lawyer, had first hand experience and I was always curious I asked many things about this a while back. Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people. You can never get to 100% recovery like that, but everyone knows who their neighbor is, at least in a town that is small like this.
So they rebuilt it first from first hand proof, then by testimonies, with a period of counter claims available IIRC. For sure there were some false claims, but given the magnitude of the disaster, this is the best solution within that context.
> Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people
In a similar vein, I was once curious how you would prove your identity if ALL of your relevant documents (passport, driver's license, birth certificate etc) were lost in some kind of cataclysm e.g. a house fire pre-digital etc
Turns out there is actually a mechanism for this:
- get multiple people to sign sworn affidavits that you are who you say you are
- that begins the "paper trail" of evidence that allows you to start getting the rest of the document chain
- you rebuild from there.
If you're married, there is already a similar process for when a spouse takes the last name of the other spouse. The marriage certificate is the first step and then it goes from there for driver's license, passport, credit cards and so on.
Fun fact, if you're unlucky enough to replace your Social Security card 10 times, they will no longer issue them to you anymore. It is a lifetime limit, and they fan it out to 3 per year.
Oddly enough, if you legally change your name, they will send you a new one regardless of the limit.
The circumstances in which you actually need to physically present your Social Security card are quite rare indeed. In fact, that is the first thing I was told by the ssa dot gov site, when I applied to receive a new card.
It is very unlikely that you will be asked, even by a prospective employer, for your actual card, because let's face it: it doesn't even have a photo, or anything but that unique number on it. Anyone trying to authenticate your number should be satisfied if you can give them the correct number.
And just for review: SSNs are not a "national ID" and you're typically not required to divulge it to private parties, and they can make up some other unique ID for you in their database. It's usually just a shortcut for them to do a background or credit check on you. And that's not something for which they would need your physical card.
That being said, I've replaced my card about 3 times now, and it was comparatively difficult this time around. The first time, I did it all through the mail (the process of building up from no ID to get birth certificate from out-of-state, to the SSA card, to the in-state driver license.) and the second time it arrived by mail, no hassle.
But this time around, even though I applied online, I was directed to make an appointment at the field office and physically walk in there, to prove my humanity. I had never been to an SSA Field Office in my life! The experience was very chill, and there were a dozen windows serving people, while about 4 of us waited in the lobby, and I was in-and-out half an hour early. The civil servant was a lady in good spirits who was a military veteran. Big props to them!
I no longer have an SS card--which was in a wallet stolen years ago--or, perhaps, a birth certificate which I looked for recently but couldn't find. I do have a passport.
But this time around, even though I applied online, I was directed to make an appointment at the field office and physically walk in there, to prove my humanity.
I'm curious when this happened. The phrase "but this time around" makes it sound fairly recent. However, my wife had this very procedure required back in the 1990's.
She also had the same experience as you: Very friendly civil servants eager to help, and things were cleared up quickly once she understood the process.
Except for certain industries where the government has a direct interest (banking, healthcare, real estate), I don't think anyone has asked for my SSN in at least a decade. It's not like the old days when you'd fork over your SSN to rent videos at Blockbuster.
In my country (and I think by now most non-US developed countries do something similar) everybody has a CPR(CentralPersonRegistry) number that identifies you, you need it to do almost everything so you aren't likely to forget (its your birthday + 4 digits). You get it at birth or if you come to the country for more than 3 months, it legally mandatory and it's also legally required to inform the government if you change your address. Also, if you (ever) had a modern passport there is already a database with your fingerprints, face and iris scan in it.
It depends on the country. The US has the ability to do the equivalent of deep "duck typing" with almost no documentation even if you've been off the grid in the developing world for a long time. This is a case where the intelligence apparatus works in your favor. They can know you are a US citizen with high probability absent obvious evidence of such.
Of course, if you fall into a crack that is beyond their reach you will almost certainly have a more difficult time. For a variety of historical reasons, there has been relatively little reliable documentation of American citizenship so the system adapted to that reality.
I tend towards being cautious with my information which has led to beauricracies doubting my existence.
I got my first passport at a formative period of my life (international travel does that). I looked nothing like the photo within aa year. It served as a passport until it expired but only created skeptisism as a photo ID.
I don't know how to drive, so do not possess a driver's licence. I am in a 35+ year relationship, but unmarried.
The only purchase I have made on finance was a bed that I immediately paid off because the the only reason I did it was to establish a record. This was surprisingly difficult to do because they were reluctant to let me have the bed on finance because I had no credit record.
I finally had to renew my passport when I bought a house. It was the only way I could meet the id requirements.
Prior to that I was leveraging non-photo id that could only be acquired with photo-id. It seen that will be accepted in lieu in many instances and allows you to get more similar forms of non-photo ID. All you need to get started is to find a staff member fed up with the ridiculous rules enough to click the checkbox to say that they saw a photo ID. It helps that many of the staff in these positions are more aware of security theater than the general public.
Being a land owner means a lot of those days are peassed, I can't really prove I am the person who is recorded as owning the land, but mostly organisatipns are happy that I am claiming to be someone they know exists.
Linkedin has stopped asking. I'm not sure if that means they think I am a lost cause or that anyone not on their books by now doesn't actually exist.
So for many years I only paid cash for everything, but I hit a point at which I wanted to start establishing credit. What I did was to open a secured credit card at my bank. They actually had me put it in a CD which was used to secure it. After I think 2 years of paying on time they removed the security requirement. I don’t know if that’s still a viable method but I used it in the early 2000s.
Yeah it's actually not that bad, because for example the BMV will likely upon request send you a duplicate driver's license to your address of record. Same for getting replacement credit cards. If you had utility services at that address in your name that's additional documentation. Also historical tax returns, bank accounts, etc.
Fun fact: If your house is under 5 ft of ash, it's not covered by volcano insurance. That only covers you if your home is destroyed by the actual eruption/explosion.
What you need is "pyroclastic event" insurance to cover you for ash and lahar.
/ It cost something like $15/year when I lived in Seattle.
This basically covers the financial model of the whole insurance industry;
- get insurance to cover you for X
- get hit by X
- realise you actually got hit by Y after reading the policy small print (or you really did get hit by X, but your policy only covers you for Y)
Getting something like Volcano Insurance requires some specific foresight, I would be slapping myself on the back if my house was covered in volcanic ash right up to the point when I got on the phone to my insurance company to make a claim.
I have a 'bootstrap' system... I have recovery codes and a backup for critical things encrypted and stored in a public git repo I push to both gitlab and github. If I lose everything, I can use those recovery codes to access the things I need to recover my digital identity.
You can get back your phone number once you have a photo ID and buy a new phone. Then you should hope that your service providers aren't secure enough to have disabled SMS-based account recovery.
If you're married and Jewish, the wife's mother keeps the marriage document, so even if there is a house fire and all documents are lost, your mother in law usually lives in another house, so you can pick it up from there.
I’m married and Jewish. It would be pretty surprising to me if my wife’s mother had even seen our marriage paperwork let alone possessed it. This also isn’t a tradition I’ve ever heard of in my family.
Or did a joke about overbearing mother in laws just go right over my head.
Do the people who sign sworn affidavits already have to have proven identities? If so, then they're unable to recover from a situation where they lost everyone's identity.
A great-great grandfather of mine was mayor of a town through which the front passed twice during WWI. All that survived were basements. Your father's account more or less describes the process by which the land was reparceled.
It's one of those "programmer misconceptions" - we want to make reality fit our neat and tidy list of rules/laws/code; but it's the other way around most of the time.
There are also physical markers in the ground at the corners of most properties. So if you had to, you could send a surveyor out to recertify boundaries. That would get very expensive quickly, however.
Generally, those markers are placed by the person who did the previous survey. They’re not really official designations of anything. However, if you look around, you will find things called survey monuments. Sometimes they’re embedded in the sidewalk, or the middle of the road. Out in the boonies sometimes there’s a little concrete pedestal that has the marker on it. Anytime you look at a recorded deed you will see a legal description of the land and generally that description will start from one of those monuments.
It's usually a piece of steel rebar/round stock or pipe, maybe with a yellow plastic cap, or maybe not. Usually buried or not very visible, I'd guess the surveyors find them with a metal detector.
This is true most places in the us. Have you looked? You often have to dig up the stake. It helps to have an idea of where it should be before you start digging.
Most of the us has it like that. Some of the early states still do 'nw to the stump', a stump that rotted away before 1800... The newer states learned that lesson and land is to something more likely to last and hard to move. Metal stakes are most common. Though most people are not aware of the stake since there is no reason to look for it.
I'm not aware of corner markers being the standard, at least in the central and western US. For rural and undeveloped land, oftentimes you can pay the surveyor extra to put up corner markers though, which is a good investment if you plan on fencing the property
Wouldn't work in a city like NYC where nobody knows their neighbours and a chunk of houses are empty and only owned by shady shell companies as investments...
Shady shell companies do an excellent job of proving ownership -- it's the only reason they exist! So if NYC is hit by an asteroid, you'll find backups of all the important papers neatly filed away in Delaware.
Not saying that this is the only reason, but it is a big reason why we have a land survey of our property on hand on paper and stored online. If something ever happened to the registry, we could at least establish our claim to our land.
Recorded deed will more or less universally contain a legal description of the land. This does, in fact, defined the illegal outline of the parcel.
A survey is little more than marching out into the field and putting at the location where you believe the boundaries to be based on your review of the legal description.
Of course that’s not the end of the discussion as to boundaries for reasons like adverse possession or busted titles but on his own a surveyor is going to tell you basically nothing.
Very place dependent and not so universal in my experience. Where I live the title/deed just has street address. A completely separate agency holds the plot map that links addresses to physical measurements.
Surveys, at least here and I assume everywhere, also contain parcel numbers, the neighbor's parcel numbers, and the legal owner of each parcel's name right on the survey. Along with the date of the survey. I live in a pretty rural area where 20 acres is a small lot, so having proof of where the property lines are tends to be just as important as the title.
I always wonder how things would be reconciled if something similar happened to a bank. What would be the simplest way to ‘download’ one’s balance whilst proving that the downloaded files were signed by the bank?
In my country, titles are always issued in duplicate. The land registry gets one of these originals, and the landowner the other. Just about every landowner has their original on their person, or held by a bank if it's mortgaged.
So all is not lost if the registry goes up in flames.
Happened here about 30 years ago with a fire in a council planning office. All building plans and records were lost. It was enormously useful because there was no way to prove that that house addition there wasn't approved or in any plans. Fans of Yes Minister will know the appropriate quote from Sir Humphrey.
Remember the xerox-scandal years back, that invalidated officially scanned documents. You already life in a world where "scanned before" means you can legally challenge the validity of a document.
Yes, several national archives where affected on all settings. If a institution scanned and archived documents with these- these documents are - in theory challenge-able in court- within reason..
I am pretty sure I was bitten by this bug, or a similar bug, on an IRA transfer form that I uploaded to a bank. On the scan that I uploaded, one digit in the account number was a clean "5", but the customer service person said it looked like a good clean "6". I presume their document management system was an outcropping of a system originally set up for dealing with faxes, and used that or a similar compression algorithm.
I don't know what you mean by "hold up in court". This seems to be an instance of software engineers making sweeping prognostications about legal matters.
"Hold up in court" as in was it duly executed and filed by a certain date, regardless of the time and extra management required for the bank's performance? Yes, why not.
"Hold up in court" against someone claiming it was an unauthorized transfer? Even without the bug, that can be contested in many straightforward ways!
But unless there is a specific legal claim that hinges on the bug being significant, it's pretty irrelevant "in court". I knew about this precisely because the transfer failed to go through due to redundancy - one digit in account numbers is generally a check digit, plus account titles and whatnot.
In general you can always challenge the validity of scanned documents, regardless of known software bugs or not! Just like you can always challenge that a paper document is a forgery. You need a specific argument and some evidence though!
If its at least somewhat recent hopefully those affected still have paperwork for any property ownership transfers. Finding proof of property you bought decades ago would be a huge pain.
The problem is that everything will potentially be under dispute, since anyone can claim they purchased a patch of land whose registry was missed in the restoration
Don't know exactly on it works in Romania, but proving you purchased a patch of land is a different question -- for that you have the deed. You then submit the deed to the land registry. So this situation could at most result in the seller being able to sell the land more than once or disputes over the priority of sales over liens and other competing acts subject to registration.
The United States is rare. Most countries (seemingly including Romania[1]) have adopted either a cadastral/Torrens title system in which the land registry is definitive legal evidence of who owns a particular piece of land. If you purchased a piece of land and that wasn't recorded in the registry, you are SOL because registration is what conveys title.
The United States on the other hand has a massive title insurance industry, which wouldn't exist if this system was implemented. So you can make random handshake agreements all you'd like and sue over it.
Here in Brazil lots of people deal land by word of mouth. The country is just too big and there isn't enough state present to make every transaction official, so people shake on it, draft an unofficial document and actually living and developing the land over a long period of time is what consistitutes ownership.
It doesn't take much. A neighbor and I just had to deal with a bunch of property line confusions in the US where a property subdivision 25 years ago wasn't handled correctly. None of us really cared but it would matter in the event of an eventual sale and it cost thousands of dollars in surveyor and legal fees.
ADDED: We also had a bunch of easements and cooperative maintenance agreements that were only partially documented in the deed and mostly done via a handshake. So we got that all squared away in the expensive binder from the lawyer.
The public public land record in Croatia is notorious for being outdated and poorly maintained. Basically, the last time it was properly maintained was during Austria-Hungary a century ago, or at least that's the popular opinion. Right now we have the cadastre and the land registry and they do not always align.
And for your example of unofficial agreements, the land my father and his brothers inherited is still in my grandfather's name, he died over 20 years ago, now my parents are aging, and there is just a verbal agreement on how the property is divided.
This is well documented in the the book "The Mystery of Capital" by Hernando de Soto. When it was published I thought it would change the world, but apparently nobody cared. :-)
In his thesis, this is the reason capitalism cannot work well in Latin America and other nations around the world. He says that registered land ownership is the foundation of capitalism. This is how one can borrow money against your land and invest it to make more capital. Very common for example with farmers in N. America to borrow against their farm, for machines, seeds and fertilizer.
The reason capitalism cannot work well is that it assumes endless resources and infinite growth, not because people don't like electronic transfers. Capitalism is failing in all countries and those that are not are already transitioning to some form or another or post consumerism.
De Soto describes the exact opposite situation. Latin America inherited Napoleonic property law, which only recognized property ownership when formally registered, which required quite alot of red tape. It was impossible to transfer ownership without registration. Moreover, any defect in prior registration meant the lawful owner might be the heirs of someone generations ago. Most property "owned" by the peasantry usually had defective and incurable title, having changed hands in informal private agreements, which meant banks wouldn't accept it to secure a loan. This meant only the aristocracy could leverage the financial system, because they were accustomed to following all the formalities. What piece of real property someone thought they owned, even if occupied for generations, was often in the eyes of the law owned by some aristocratic family or the state.
He contrasted that system with the American common law system, where title could be legally transfered entirely privately. Disputes are handled by courts which look to the timing and substance of transfers. Moreover, adverse possession meant that after a number of years (well within one person's lifespan) nobody could come along and claim title because of a defective transfer (even if in principle they had a better claim originally), securing title in whomever held it, even if it had been transferred without even following the much looser requirements under the common law. A bank would issue a loan so long as you could prove you held an unchallenged title for a sufficient number of years. ("Title" was whatever piece of paper handed you by the previous possessors; no government stamp or recordation required.)
Registration systems in the US are a recent occurrence, and they overlay the traditional common law rules.
A gross generalization, but Napoleonic civil law systems emphasize formal transactions centrally administered by the state, while the common law emphasizes looking to the substance of private transactions, and usually only when a dispute arises (otherwise you just presume they're valid). Broadly speaking, De Soto argued the latter tended to favor the common man, because it was much less rigid.
De Soto also pointed out that US Federal Land Grants also did a decent job at distributing land among the people, unlike Latin America where mostly only the aristocracy held land under a good title.
Sorry to break it to you but we are past end game since possibly the dot-com bubble.
"Cannot work well" and "cannot get started" are two different things. The whole of Latin America apart from Cuba is capitalist, for better or worse, regardless of how bad those countries keep their books.
If De Soto is correct, and I am not qualified to judge, based on your statement about land ownership in Brazil, then capitalism was not fully developed to where it could have been. Get the book. It's an interesting read.
And yes I can see that we are at the end of an era. This may be more the end of the U.S. empire than the elimination of capitalism, but for sure a new 'ism" is going to be required soon. What that is will be interesting to see. It would be nice to see someone with imagination come along instead the bipolar options we are handed today.
That’s how it works in the US too. We don’t record documents with the county recorder to make them official, we do so to provide notice to third parties who might purchase the land.
You’re going to need more than just a claim to prove that, and anyone who did purchase land likely has some evidence in support, even if it’s testimony from others.
e.g. if you made a big buy there ought to be records of a bank transfer, mortgage, etc.
"i paid for 30 acres here at $xx rate, and here is the mortgage docs from the bank dated March 19th that I signed, plus their valuation of the property and what went into it"
Lots of land deals aren't dealt in money transfer either. It's sometimes cash, livestock transfer, other realstate or durable goods like cars or machinery.
It depends. In my country the online land register data is just a copy of the physical land owning certificate. The physical certificates (1 for the owner, 1 for the local government, and at least 1 more for some document keeping agency) are the source of truth.
Quite likely the opposite: a few weeks ago a ransomware attack halted ~100 hospitals' management systems in Romania, and the cybercrime defense unit just disconnected all hospitals and had the local admins rebuild from backups and paper trails. So I'm quite sure that all public administration IT admins have been running drills and probably have up-to-date backups.
I'm skeptical that they not missing at least a week's or so worth of land title registry transactions, if the only thing they have left is offline, because offline backups are not made after every single transaction.
If the hacker was targeting the erasure of a particular recent transaction, they may well have succeeded. And by deleting numerous others, they have plausible deniability in the subsequent dispute over the property. If you just wipe a record that is related to you, and the manipulation is discovered (which it will be, one way or another), you are part of a narrow circle of suspects.
> offline backups are not made after every single transaction.
All you need is an append only tape or even a printer.
Interestingly in the Bangladesh Central Bank hack they used a printer to print out any transactions, but the intruders disabled it or it was just malfunctioning because it's a printer.
But I doubt the Romanians actually had such a system.
When I worked at a stressful place I was worried not only of our version control getting damaged but also someone deciding they had had enough and doing damage on their way out.
I had a copy of our code on media in my desk labeled “promotion” and updated it every month. In retrospect someone going through my desk would have assumed blackmail material and been disappointed to find only code.
I wonder why the say "appears to have had," is that an assumption or was it stated somewhere? Without an offline backup, it would indeed be a very serious problem, more than it already is.
I think the "offline" part is what is that "appears" to be, clearly they have backups somewhere, but maybe the attacker just missed to wipe some other "online" location.
Has not digital data always been a secondary source of information, instead of a primary source of information? Paper records cannot be thrown away. And new records are probably recorded digital only but a copy is sent to the parties in the transaction
At least in my EU country, no the digital record is the primary.
When you buy property you get a deed for the land, but the details of a property can change after that. The deed also doesn't contain ownership, it just says what is on the land. It's common for land to have multiple owners (1/32 is not unheard of) due to inheritance.
I'm building a house, the land deed just has the land plot as we bought it, until the house is 100% finished (and registered) we will not get an updated deed, although the digital system has newer data (you need to register the construction progress).
OK but the primary record itself is not the primary record when challenged in court; subject to a change order; redefined by legislation or handled in many other ways. There is money involved.
Any country big enough was moving digital first/digital only for years. And with a paper records there is always a question if this one is the last one and contains a valid data or it's from years ago and since then everything was changed multiple times.
Just recently I've seen a 30 y.o. deed on some commercial property. Despite it was valid and predated the digital era, it had almost nothing common with the things on the ground.
Squatters, boundary disputes and rent defaults happen all the time.
Plus having most of your net worth locked up in something no sane person would consider buying off you because you can't prove you own it is ... suboptimal
People can come and cut down trees, use the land for their cattle, raise crops or just start building something. If you don't challenge it and they get away with it for a while, they could even gain use of the land legally.
After the tsunami that hit Thailand and wiped out many fishing villages on the Pacific coast, the people were evacuated but as soon as they returned, they found the local mafia occupying the land, and as they had no need and there was no land registry, they were forced to rebuy their land.
"Under normal circumstances, property law in England and Wales dictates the original owner cannot claim their property back even if the title change was made fraudulently."
That's... a curious thing to have in the body of laws. What's its purpose and who does it serve?
That’s a simplified explanation. Title insurance covers a number of situations, fraudulent transfer of title is only one of them and is more likely to be something like “A wife sold her dead spouse’s house, but it turns out that there was a dispute about the will and now someone else is claiming that the house actually wasn’t hers to sell”
That wouldn't be possible in my country because she would not have any right to sell the house until it was transferred to her. This transfer would happen during the probate process. The probate process is where all issues regarding the will/estate and disputes are settled. Once probate is complete, ownership is set in stone and the widow would have every right to sell her house.
The sad part is, the whole world worked perfectly fine without anything online, ever, prior to 20 years ago. Even 10 years ago for slow-moving change.
It's literally not a requirement to have it all online. And the cost of developers, plus coding + security updates + platform costs, really just means you replace a few assistants which would process requests by hand, with all that.
Except? It's a lot harder to hack a person to delete all the files in the office, from 10k km away, than via a computer.
So many things simply don't need to be online. So many things simply are better archived by other means. So many things are safer, more secure, and the backup processes (microfiche, etc) are well understood and just work.
There are many examples of important paper records (property, birth/death, etc) being lost in fires or floods, so it's not the case that "everything worked perfectly fine" in those days either.
All those examples are not different from not having backups of digital data too. Making copies when you microfiche, having duplicate stores, it's all exceptionally easy and a solved problem.
And of course everything didn't work perfectly, it did however work "perfectly fine", which means "very well" or "good enough". Meanwhile, adding in network connectivity to anything vital these days is just insanely dumb.
No software is secure, and will never ever be secure. Ever. Anyone who thinks that software can be made secure, is 100% wrong, period. My point is that the advantages aren't worth the disadvantages.
Your overall assessment of advantages and disadvantages seems like you're comparing paper with backups to software without backups, though. No competent system can have all the records destroyed remotely. And we know how to backup digital systems even better than we know how to backup paper ones.
And as a third option we can have efficient digital systems that aren't plugged into the Internet. (Presumably the Internet could have a copy that's regularly updated.)
I agree that digitalization is not a panacea, but things did not work anywhere close to perfectly fine when everything was on paper. There are just as many ways for analog/physical processes to go wrong.
A sophisticated genius hacker in a different country can’t touch your paper records, but an absolute moron with a bic lighter can destroy records just as effectively. Hell, an irresponsible clerk can do an incredible amount of damage just by misfiling things.
Duplication literally doubles costs in the physical world, and has the downside of being very hard to keep in sync. A bank keeping paper ledgers would be absolutely fucked if they had to switch to a backup ledger that was more than a few hours old.
On net, I believe that digitalized documents are a net improvement.
Yeah, while online copies are a risk, you can make offline digital copies of important data for a thousandth the price of paper copies.
Put some desktop-size tape robots in several government building closets, and task someone with switching tapes weekly, and you can achieve more reliability than multiple huge paper archives.
Yeah, we’re early culturewise in the digitization experiment and high on optimism about the benefits, but not very far into reckoning with the downsides and incentives skew a bit towards carelessness.
The real danger is that we’ll be so careless we’ll discard other enduring ways of doing things before we smarten up to their particular benefits.
My hope is that disciplined people still have an intuition for this, even among the digitally steeped. Sysadmin/ops types tend to a culture of diversifying backup location and even media type. Maybe that can reach back to human legible hard copy.
Everything comes with a risk, and people usually take it with a decent understanding of how to mitigate it mostly.
If we start thinking along the lines of technology has risk and we shouldn't use it, we should go back all the way to the discovery of fire as we all know fire can cause a lot of damage if in the wrong hands.
Technology can make lives safer. However, software is never secure, cannot be made secure, this is empirically proven to be a 100% valid position.
In as software is not secure, and can not be made secure, using it for important records storage makes zero sense, unless you a) have full backups offline in physical, non-digital, read only medium or b) just don't do it online, at all.
Read the scope I discussed. Physical records can be made exceptionally secure. They can be secure on location (archival location, with guards). They also aren't reachable by every human being on the planet who wants to infiltrate.
Think about it. To destroy the public archives, of which there is typically more than one, you must travel to said location, breach it with weapons and other means, and destroy it. Or, you can sit in your parent's basement in your pajama's, and hack and destroy.
There is not even remotely the same risk profile.
And if you think something is "good" because 'the world thinks it is good', then I have to ask you why you're validating something via popularity. You know what else was popular? Fossil fuels. Smoking. Using uranium in makeup for women. Something being accepted, and being fun or convenient, doesn't make it correct, sensible, or right.
So please describe the horrible and incredible "gigantic convenience". Because I lived before the internet, and now after, and yes it is convenient.
But it certainly isn't a 'gigantic' one, nor is it sensible compared to the insane attack surface and risk.
A backup that isn't offline is not really a backup as it far too easy to destroy it even by accident/carelessness/lack of understanding.
When I was responsible for backups we kept the tape cartridges in a fire safe in a different building. We took a full backup weekly and moved the tape from the robot to the firesafe as soon as the backup was complete. Only the daily incremental backups stayed in the robot for more than a day.
That sounds good, but wouldn’t you worry that the same hackers will let themselves in via the same route again?
You would need to understand first how they gained access and verify that they can’t do the same again. That in itself could take days if not weeks. Then of course they might have found new vulnerabilities while they were in, so you would need to worry about that too.
Only if you routinely test it, and if that kind of access to the offline backup is low friction enough to be doing that monthly, it might not be enough of a redundancy.
The most time consuming part of recovering from an attack is validating everything. It takes more than a few hours to validate the infra that stays put isn’t compromised, the IaC code itself isn’t compromised, deploy the infra, bring a copy of the offline backup of your data (your IaC can’t drive to another site and bring the backups, then make a copy, unless tou are really sure you removed any trace of compromise), validate that the backup is sound, then restore it.
In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.
> The most time consuming part of recovering from an attack is validating everything. It takes more than a few hours to validate the infra that stays put isn’t compromised, the IaC code itself isn’t compromised, deploy the infra, bring a copy of the offline backup of your data (your IaC can’t drive to another site and bring the backups, then make a copy, unless tou are really sure you removed any trace of compromise), validate that the backup is sound, then restore it.
> In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.
Your IaC is supposed to be on those offline backups too, and should be able to do everything from clean hardware.
The most time consuming part is to identify what caused the compromise. After that, you can put everything back online and then at the same time start to analyse who did it/what they did and so on. If the root cause for the breach is identified, you also know the time most likely and can trust the offline IaC backup.
An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):
ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.
After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.
ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.
According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.
The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.
The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
My ex was late from work once a week because the company did commercial real estate logistics (sort of similar domain here) and she had the job of going to the secure data center and grabbing a backup disk out of the cage and transferring it to a safety deposit box.
The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or all three. The owner kept a second copy at his house, and that was the only geographically separated copy.
>it had begun migrating its applications to Romania’s Government Cloud
This proclamation, coming from a governmental organization, makes me afraid they are doomed. Effectively they are saying they are fixing the mistake by repeating it.
What they should do is admit fault. Freeze the system. Get independent expert help.
Best wishes, recent Romanian land buyers and sellers
They are getting expert help. I expect that the agency maintained their own local deployment on infra administered by its own employees. Now they are migrating to the central 'government(-maintained) cloud'.
At the same time they are working with authorities.
As a Romanian I can tell you that most of the corruption happens through "dedicated contracts", or outright syphoning.
In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.
If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.
If it is any consolation, this kind of corruption exists in many countries. I don’t know how to fix this, but corruption always finds creative ways.
Here is one I learned recently - govt started issuing birth certificates online. Hopefully Less corruption, right? Officials made deliberate spelling mistakes in names etc, because you have to go in person for corrections. In person means bribe, which means back to same situation as before (almost)
Problem really is that things like SSN or ID numbers should have never been treated as more as just one possible semi-public unique identifier. Never anything to be used in identifying a person for a contract.
There is a somewhat valid argument to be made that aggressively trying to hack these insecure government portals could lead to a real reprioritization towards competence.
I'd say form an IT firm and bid on government contracts and do honest work, but we all know how that goes in reality. Honest workers don't get the contracts. You can still try, though.
I'm sure it's obvious to anyone living in a corrupt/oppressive regime, but in case it's not obvious to everyone.
Corruption and oppression are signaling and coordination problems. The illegitimate sovereign is exploiting informational assymmetry: they know your neighbors are just as angry as you, they know it because all the walls have ears.
They need to prevent you and your neighbors all knowing it at the same time. Your best play is to find some signal, something difficult to censure, hard for the goons to pick out in a crowd but legible to your neighbors. If you all knew that the first guy to shove back when the cop shoves you is going to be followed by a swarm of guys? Very easy to find the first guy in that case.
This is why shit like extremely high gas prices scares the shit out of illegitimate sovereigns: they're the ones posting pure data about why everyone should be that angry right now.
A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
Its a bit more nuanced than that. The company responsible for ensuring the cybersecurity of the system told the press that "they secured what the client told them to secure and it was not their job to tell the client what needs to be secured".
It's always amusing how this is always attributed to the corruption.
It's even more funny on Reddit when you can see the person who is blaming cronies in his Romania but has posts of him doing some blue-collar work in the Midwest.
Well, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit too
Tangentially reminds me of what happened to the South Korean gov data center [1] where a no-backup ~900TB data center got erased due to a battery fire.
Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.
Last i heard i think they had restored a quarter of the lost services/data.
The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.
That was my thought exactly on reading that line: that is not a backup. (Ok, the word isn't strictly defined, but you know what I mean.) They have said there's a "real" (offline) backup as well, luckily, but that just reinforces that the "pretend" backup was irrelevant and wasn't even worth mentioning in the writeup.
- We have 2 sources of data that we must backup to continue existing as a business; our postgres and binary files in S3. Everything else is derivable (elasticsearch, so on).
- For postgres, we use barman. With the help of opus/fable, you can get a streaming replication backup working in no time. We have one into another server in the same datacenter (we use baremetal) and another one in another server in a different datacenter.
- We then have a last resort barman backup with bi-weekly base backups + WAL streaming to S3 (both the base backup and WALs). It sends these backups + wal segments into an specific S3 bucket that has object lock in compliance mode. This is a feature from AWS S3 that even the most privileged account credentials (super admin) can't turn off nor delete the files before the object lock, which is 10 days in our case. Object lock compliance mode can only be extended, never shortened.
- For S3, we store them into another versioned bucket, with lifecycle rules to also expire non current versions (== deleted objects) after 10 days. No point in object lock compliance here because it would only protect objects for the most recent 10 days, and you gain nothing. What we do instead: the app servers only have access to these bucket tru an IAM credential that can't delete old versions (so deleted objects have to expire manually via the lifecycle rule) AND this IAM credentials also can't change the object policy.
IMHO, this protects us enough so that even in the worst case scenario (ransomware) we have 10 days to sort everything out and recover our AWS access.
And yes, we test the S3 barman restoration and it works fine. Data loss is at max 5 minutes due to the archive_timeout=300s on the primary.
For the streaming replications in the two servers I mentioned, it's less <1ms, but those wouldn't protect us much in the case of the ransomware - even tough we use tailscale and one compromised server can't ssh into the other.
The Slovak land register was hacked in January 2025. Hackers uknown encrypted the database, asking for an undisclosed 7-figure amount as ransom.
The whole country's real estate market was paralyzed for about a month. It took couple of months to restore everything from backups and paper agenda and resume normal operation of the land register office.
It was the largest cyber attack in Slovakia's history. The authorities to this day haven't provided any information on who might be behind it. The investigation is still ongoing. Several government figures including the PM were however very eager to immediately point on Ukraine, without any sort of proof.
If I remember correctly, this is the hack that Fico tried to blame on Ukraine, even if the hackers were a known Russian ransomware crew that literally posted in their Telegrams about their support for Russia... right?
Ukraine was specifically mentioned in two of the articles I'd referenced, though not in the one originally submitted to HN. I was dubious finding it once, hedged with "apparently" based on the 2nd. I did look for a Wikipedia article on the event which might have included a more substantive and reflective post mortem but didn't find one.
If you've specific information clearing or establishing the link, post it. I agree that hasty accusations are risky. The main point I was looking to establish was that the source wasn't indicated as Algerian, as with the Romanian incident.
it took months to go back fully online. they also had usable backups (so they used those for the data), but the infrastructure had so many vulnerabilities that they had to fix it first, hence the delay
Property is not fluid and doesn't change hands very often. Sure, in a large enough market lots of activity happens every day, but any given property is only involved in a transaction once a decade. You can have very old backups and still capture the state of the market to 99%+. Any recent activity will have brokers, buyers, and sellers, who all have current copies of their activity.
Also, this sort of event should result in some hackers being found and jailed for life as well as their families being bankrupted permanently. Or, if they are being protected by their government, this should be considered an act of war and an appropriate military response should be delivered.
This wouldn't be a bill of attainder, it's simply an infinite assessment against the criminal's estate that can't be discharged in bankruptcy. I don't personally think that people should inherit their predecessor's debts, but I have no problem with debts being able to capture the entirety of a person's wealth including homes, pensions, jewelry, trusts, any accounts from which benefit is drawn, etc.
NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.
For me the first 2FA devices I’d had were for work but for my friends it was for a world of Warcraft. And it was years until my bank offered 2FA. I still think about that every time there is a breach.
Blizzard gave hardware tokens out to the entire convention one year. Smart phones became a variable not long after and then they didn’t make them mandatory but game guilds almost universally did. Especially for officers.
The UK used to have a distributed system - everyone had to have a solicitor store "deeds" of their property, which were a sort of paper blockchain of all the transactions the land had been in since - I don't know, since records began I guess. Since we got a centralised land registry cheaper solicitors have binned these, but some properties still have them as a historical record.
Not sure what you mean by 'binned'. In some Common Law jurisdictions the deed document represents the property and whoever psychically holds of the deed controls the property. Any centralized recording system merely records the last known status of the deed and additional information such as the nominal owner, mortgage holders, etc.
Not sure if by "centralised recording" you are referring to the UK way or how it is implemented in general (civil law) but I can say that in Brazil the registry definitely does not have only the last deed.
In Brazil the books are append-only, they have the whole history of thay piece of land since records began. If it was a bigger plot that was dismembered, it is there too. When ownership changes you have to register the contract/terms of transfer/sale separately in a different process, but that does not change legal ownership and you still must go to the registry and register that registered transfer/sale in the registry, and the paperwork you get is a new certificate of registration which is a new snapshot of the books and includes that whole history from the very beginning. There is no copy or certificate you can can get from the land registry without including that whole history.
In the UK, the old common law
rule does not apply to land that has been registered centrally, that is then the legal definition of who owns the property. However there are still properties that are not registered and for those, the rule you describe is still applicable; the holder of the deeds is the owner.
Registration is now compulsory on sales, but that only came in in 1990.
As to what I mean by binned, I mean literally binned, thrown away.
Offline and pull based backups FTW... This is why I advocate for a pull or at least push/pull model for backups... where the remote system pulls backups out of your production environment, or otherwise from a drop point. Because a corrupt production system that controls backups can corrupt backups.
If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups from there, you can better ensure older backup files are intact. More so by not allowing the two to see each other at all and not using backup accounts from a system that can access production resources.
Under the Australian Torrens title system, paper is no longer authoritative and if you bring a deceased estate title document to the registry they keep it after updating the titles registry database, unless you ask to get it back and it's stamped to mark it superseded. I know because I've done this journey.
The majority of people have paper documents from the land registry. Digitalization of the land registry is a fairly recent development in Romania so people almost always requests papers when they register their land. In the event that all the digital data or large parts if were lost it would be possible to reconstruct it from the papers and interpolate the missing parts if any.
> HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models.
This, to me, is the more interesting bit of the article.
I don't really know what a good solution looks like, but yeah, that's annoying.
we spent centuries building a system to track who owns what land and then put the whole thing in one database that can be deleted with a single compromised password
arte.tv released a documentary about measuring and registering land just a month ago @ https://www.youtube.com/watch?v=fl7AfiJs5Gk (Romania: The Unmeasured Land | ARTE.tv Documentary)
local admin credentials or two factor or the BEST is a immutable time-lock, so a snapshot cannot be deleted before the retention period that was set when it was taken expires
Seems to be rather sturdy in my experience. Would we even be able to read an electronic record after 100 or 200 years of storage? Old piece of paper is quite accessible.
Documents getting lost/misplaced/stolen/destroyed is common in some places (owing to corruption or what). "Local in scope" but rampant. Digitization has been a panacea as there is more control over the records, but now more prone to hacking.
And you need to know how to read to read paper copies. Same thing, essentially. Anyone speaking hieroglyphics fluently? Point is, if you take care of your archive and make sure it remains accessible, it doesn't really matter whether it's digital or analog.
Not at all the same thing - what equipment do you need to read hieroglyphs on top of understanding the language (which goes for digital, too)? If you have the paper and understand the language, that's it. We already can see that accessing old digital data isn't necessarily easy if it wasn't always kept on/converted to current media and formats (will we keep that up for millenia)?
And both storage can be broken, needing reconstruction.
If I were to give you a 70y old book in English vs some 70y tape with data on - which one is easier to read?
For the third time: IF you take care of the data, it’s fine in both cases. If you neglect your beloved book for 70 years and store it under a bridge, it’s going to be completely useless as well. The key part is the taking care of your medium.
The taking care of the book for 70y does not involve recreating the book over and over again to keep it readable or keeping a reading machine in working condition (or be able to recreate it). It's an entirely different level of care.
If the medium isn't destroyed, it is directly readable if it's a book, but not necessarily so in digital because hardware and software is needed - just taking care of the original medium isn't enough in digital over centuries.
There have been plenty of instances of paper-based land registries being wiped out. It's just usually a very local problem because paper lends itself more to decentralized storage
Yes, so quite limited in scope. We have no experience with storing and keeping accessible electronic records for hundreds of years, though, but we know already that accessing old storage media and formats isn't necessarily easy.
So far accessing old storage media from 50+ years ago hasn't really been a problem. Reading old tapes and punch cards/tapes or even early hard drives is something that a single motivated hobbyist can achieve in a few weeks or months with a microcontroller and patience.
But it's more difficult to imagine that 1000 years from now someone will be able to read from a PCI-E NVME drive if the specs get lost along the way (ignoring for a moment that flash storage most likely won't retain data that long).
I would not call needing weeks or months not a problem (assuming you also get the potentially proprietary software to understand the data recovered). Also, early hard drives weigh 100s of kilograms, so just physically handling them is difficult.
Hackers would do it from the operating system level - stop the database executable, then delete the files used to store the database. Likewise, many organizations store the backups on a network share, where a hacker could delete the files.
Permissions inside the database should be segregated. The credential used by the webserver should not have enough permissions to DROP DATABASE. Just the appropriate selects/updates/inserts.
Likewise, if you are storing backups on the same network (as opposed to a tape backup), network permissions should allow writes/creates but not deletes.
Why is deleting a row in a table a valid operation? Why is deleting a table in a schema a valid operation? Most likely they had full privileged access to the database.
I understand that many software projects don't understand the principle of least privilege and make god users that can do anything including deleting everything.
... and an incorrect password policy and poor access control. Usually, in these institutions, if STS is not responsible, there are third-party companies, usually proxies, that are responsible for managing the firewall and accessing the data. The lack of procedures and lack of supervision from the authority, combined with the delay from the service providers, leads to a situation where everyone does backups as they think is best. That's why it takes so long now, because STS restores data from different formats, from different places, made at different times
There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.
Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).
It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)
The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.
As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).
I don't think that most competent IT people are pushing for digital-only systems. The people that I see pushing for digitalization are either clueless politicians or corrupt or incompetent IT people selling snake oil. The sad part is that the snake oil sellers are probably a majority already, so fighting against politicians and snake oil sellers is a tought one.
Amateurs. Everybody knows you should never wipe databases. You should install a cronjob that makes a random, unrecoverable change on a regular (but random) basis.
We had that almost 80 years ago for a few decades, but we shot a guy at the end of it. I hope the next one to suggest something like this remembers the history and refrains from it.
It did help the West, and especially the UK, to get as immigrants very high good plumbers and handy men. The rest of us went into STEM and are now working for FAANGS.
Capitalists say "you will own nothing" and want a Gini coefficient of 1. Communists don't say "you will own nothing" - they say "abolish private property" and refer to a Gini coefficient of 0.
Finally, AI is giving us some real-world blockchain use cases (assuming the attack was helped by AI). Only half joking, BFT is petty much the most adversary-proof security guarantee we can get in a distributed system.
So that 50% attack results in someone taking all the land? No thanks.
It is a poor idea to use blockchain for government registries. If you want transparency, simply publish signed daily updates and that's enough. Just use simple DB with backups, and optionally, a printer printing changes on a paper.
Merkel tree audit log of the data, the poor man's Blockchain, works fine and good enough. Now you have a db and you can claim to use a blockchain for pr reasons.
It doesn't matter, it's a dumb idea anyway because there is a central authority managing the land registry and there is no need for anyone else to be involved.
Also, SQL database is much more convenient to use, it has query language and indices unlike a blockchain.
You can put an index on your blockchain DB, what are you talking? Every node can manage it as it pleases (within the limits of the consensus algorithm).
Yes, if you have a centralized model you don't need it. Just saying that this incident is the exact risk a blockchain is meant to mitigate through redundancy. You can say you don't care about this risk, but it doesn't change the truth of the statement.
Yeah, the overwhelming majority of the benefit of blockchain here is just gotten by making the data public and signed.
Now you may argue "that is a blockchain, not every blockchain is associated with a shitcoin" but to be frank that ship has sailed, if you wanted to defend that you'd have had to do a lot more work over the past decade.
Which could easily be solved by just making data publicly accessible. Actually I see no reason why you shouldn't be able to download land registry say every month. Same actually goes for any stock ownership in companies over certain threshold.
That is what I'm saying. And you may be right, but the security guarantees are math and math is patient. If people decide to ignore it today, it'll still be true any time they decide to take another look.
>Now you may argue "that is a blockchain, not every blockchain is associated with a shitcoin" but to be frank that ship has sailed, if you wanted to defend that you'd have had to do a lot more work over the past decade.
What do you mean by "More Work" here?
There were plenty of tests and pilots of systems like that described. Dual goals of reducing the cost of transferring property and publicly attesting all current ownership. Real lawyers and real lawmakers developed proposals to integrate these sort of services with current public land registries.
The issue as far as I see it isnt the "work" its the "antiwork". If you want to learn about land sale nft pilots you literally have to put -metaverse into the google search to weed out the metaverse nonsense. Theres just too much noise around blockchain for even the best signal to penetrate. The stupid monkey nft guys really fucked the whole space. Probably take another decade to dig out all the toxic waste from blockchains reputation.
> It is a poor idea to use blockchain for government registries. If you want transparency, simply publish signed daily updates and that's enough.
A blockchain is essentially that, just with the daily update that's being signed also including the signature and hash of the previous day.
Blockchain as a technology is actually useful here. It does not mean automatically that blocks have to be mined by third parties, although pseudocurrencies have gone that route for decentralization reasons.
Blockchain is unnecessary complicated, for example, it has mining, rewards for those who add new records, even VM and scripts and all of these are not needed for a government registry. I do not need scripts within a land registry.
> Blockchain is unnecessary complicated, for example, it has mining
depends on configuration, you can make any traditional web service replicated (replication is one and only thing that protects data in decentralized ledger, same as DNA is stored in every cell) using something like CometBFT on top. Mining/PoS or VM - all optional.
Clearly, you would scope the features and choose implementation options so that it makes sense for the use case. Mining (ie PoW and/or Nakamoto consensus) is clearly inferior to any deterministic consensus here. A cryptocurrency isn't necessary and would be a distraction. But at least some limited programmability could make sense (eg for escrow).
A blockchain solves the problem of consensus under Byzantine faults. Payments are an incidental use case, and not even a good one because managing payments including avoiding double spending can be achieved with a weaker primitive than consensus.
No. Blockchain is made for managing transactions between untrusted parties. In case with a land, there is an authority managing the registry, so a standard relational DB (with optional digital signatures) is the bets option. Why someone wants to use a tool, not good for a specific purpose, for that exact purpose?
I would be less comfortable with my land registry tied to a blockchain, as soon as I lose it (who is much more likely to) it's impossible to get my land back.
What's wrong with paper records backup up a digital record and audit trail. This all seems like a solution for a non-problem to me.
A blockchain isn't stopping you from doing any of those things, if anything it's facilitating different backup models by different parties. A paper record is so much more susceptible to various kinds of risks, adversarial and otherwise. I recommend to look past the hype or hate at the technology. A blockchain is the logical extreme of where you end up when you think about how to sync backups, and you recognize that it comes with certain mathematical limitations on how much disruption you can handle.
> A blockchain is the logical extreme of where you end up when you think about how to sync backups
It's not. Blockchains are only eventually consistent among nodes. They're designed for synced backups among adversarial peers.
There's no reason for a government agency to use one internally. There are better ways to sync backups when the people with access to make updates are also authorized to do so.
Internally, you don't need it, agreed. But that is centralization risk exemplified in this incident. Which isn't necessary. Every notary could be a node. It would be a lot more resilient, and it would look a lot like a blockchain (not necessarily with a crypto currency though) if you do it properly.
You can have decentralization without blockchain. A defining feature of blockchain is that each node depends on the precise ordering of prior nodes which is a huge liability if you have network disruptions, etc, in a bureaucracy.
A git repo with cryptographically signed commits solves all the same problems without the headache.
Agreed that you don't need total ordering and hence consensus for pure asset transfers. But if you want to make any changes at all, like updating the list of nodes, you do. So in practice, you do need it. Every other proposal will fall short in a critical and avoidable way. Amending your git proposal with the necessary parts will turn it into a blockchain.
Disagree. We're talking real estate here. The time between transactions is months to years, not seconds to minutes. A git history will work fine. If there are racing transactions against the same piece of real estate, that's probably fraud, not something that should be automatically resolved.
git as-is is completely unfit for purpose and a huge security risk for this use case, because it uses MD5, which is no longer collision-resistant.
If your proposal is 'something like git, with a few modifications to make it suitable for this use case', then that's exactly what I'm proposing. What you will need, once you've considered all requirements to the best extent feasible, will be a blockchain. Eg you do need the ability to make protocol updates, no matter the time scale of transactions.
> git as-is is completely unfit for purpose and a huge security risk for this use case, because it uses MD5, which is no longer collision-resistant.
Firstly, git does not use MD5. It uses SHA1.
Secondly, since 2017 git has shipped with an implementation of SHA1 (sha1dc) that detects the collision attack you describe, which for this use case renders it a non-issue.
Thirdly, git supports `git init --object-format=sha256` which removes the whole issue for anyone who cares to do so.
I think git as-is solves the problem nicely. The only additional value blockchain provides is the ability for someone to point at it and say "look! A use for blockchain exists!" which isn't worth the downsides it'll bring.
You can't do any real money/real estate transactions without canonical order (chain of events). that's why git analogy is not applicable here. You'd need "main" branch to be canonically finalized for each and every participant.
What? Sure you can. All you need is confidence in the current owner. You don't need the whole history. Can you imagine the poor store clerk trying to say "sorry sir I can't accept that $20 bill unless you can name every prior owner in order".
Not sure if you're being deliberately obtuse here but this isn't an issue with the cadence of real estate transactions. Real estate ledgers do not need to support HFT.
If every notary is a node, you need some mechanism to ensure they perform only legitimate transactions and constantly monitor them. It is easier to just have a central authority.
> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.
So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
This happened in a 50k people town where my father is from in 1982 with a BIG flood that destroyed the town land registry documents (among a lot of the town). Since he's a lawyer, had first hand experience and I was always curious I asked many things about this a while back. Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people. You can never get to 100% recovery like that, but everyone knows who their neighbor is, at least in a town that is small like this.
So they rebuilt it first from first hand proof, then by testimonies, with a period of counter claims available IIRC. For sure there were some false claims, but given the magnitude of the disaster, this is the best solution within that context.
> Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people
In a similar vein, I was once curious how you would prove your identity if ALL of your relevant documents (passport, driver's license, birth certificate etc) were lost in some kind of cataclysm e.g. a house fire pre-digital etc
Turns out there is actually a mechanism for this:
- get multiple people to sign sworn affidavits that you are who you say you are
- that begins the "paper trail" of evidence that allows you to start getting the rest of the document chain
- you rebuild from there.
If you're married, there is already a similar process for when a spouse takes the last name of the other spouse. The marriage certificate is the first step and then it goes from there for driver's license, passport, credit cards and so on.
Fun fact, if you're unlucky enough to replace your Social Security card 10 times, they will no longer issue them to you anymore. It is a lifetime limit, and they fan it out to 3 per year.
Oddly enough, if you legally change your name, they will send you a new one regardless of the limit.
The circumstances in which you actually need to physically present your Social Security card are quite rare indeed. In fact, that is the first thing I was told by the ssa dot gov site, when I applied to receive a new card.
It is very unlikely that you will be asked, even by a prospective employer, for your actual card, because let's face it: it doesn't even have a photo, or anything but that unique number on it. Anyone trying to authenticate your number should be satisfied if you can give them the correct number.
And just for review: SSNs are not a "national ID" and you're typically not required to divulge it to private parties, and they can make up some other unique ID for you in their database. It's usually just a shortcut for them to do a background or credit check on you. And that's not something for which they would need your physical card.
That being said, I've replaced my card about 3 times now, and it was comparatively difficult this time around. The first time, I did it all through the mail (the process of building up from no ID to get birth certificate from out-of-state, to the SSA card, to the in-state driver license.) and the second time it arrived by mail, no hassle.
But this time around, even though I applied online, I was directed to make an appointment at the field office and physically walk in there, to prove my humanity. I had never been to an SSA Field Office in my life! The experience was very chill, and there were a dozen windows serving people, while about 4 of us waited in the lobby, and I was in-and-out half an hour early. The civil servant was a lady in good spirits who was a military veteran. Big props to them!
> The circumstances in which you actually need to physically present your Social Security card are quite rare indeed.
In my state, it's one of the allowed document types for proof of social security number, required to get a real ID drivers license.
https://www.mass.gov/doc/ma-real-id-documents-checklist/down...
To get one, but not to renew it, so that's still pretty rare.
Here's a pretty good video about a somewhat similar challenge, that of proving your citizenship in ancient Rome: https://www.youtube.com/watch?v=LTt0qwncDXI .
I no longer have an SS card--which was in a wallet stolen years ago--or, perhaps, a birth certificate which I looked for recently but couldn't find. I do have a passport.
But this time around, even though I applied online, I was directed to make an appointment at the field office and physically walk in there, to prove my humanity.
I'm curious when this happened. The phrase "but this time around" makes it sound fairly recent. However, my wife had this very procedure required back in the 1990's.
She also had the same experience as you: Very friendly civil servants eager to help, and things were cleared up quickly once she understood the process.
> SSNs are not a "national ID"
That's not what they are, but that's what they've defacto become. I hate it.
Is that still true?
Except for certain industries where the government has a direct interest (banking, healthcare, real estate), I don't think anyone has asked for my SSN in at least a decade. It's not like the old days when you'd fork over your SSN to rent videos at Blockbuster.
oh ok so just for money body and property related issues. phew.
> Except for certain industries where the government has a direct interest (banking, healthcare, real estate)
That's still a massive dependance on "ID" for SS...? Blockbuster tho.. phew it's been a while.
Afterwards, you have to make an appointment to see them in person. Until then, you can order them online or via snailmail.
Wow, state of digitalization is pretty sad in Somalia.
In my country (and I think by now most non-US developed countries do something similar) everybody has a CPR(CentralPersonRegistry) number that identifies you, you need it to do almost everything so you aren't likely to forget (its your birthday + 4 digits). You get it at birth or if you come to the country for more than 3 months, it legally mandatory and it's also legally required to inform the government if you change your address. Also, if you (ever) had a modern passport there is already a database with your fingerprints, face and iris scan in it.
It depends on the country. The US has the ability to do the equivalent of deep "duck typing" with almost no documentation even if you've been off the grid in the developing world for a long time. This is a case where the intelligence apparatus works in your favor. They can know you are a US citizen with high probability absent obvious evidence of such.
Of course, if you fall into a crack that is beyond their reach you will almost certainly have a more difficult time. For a variety of historical reasons, there has been relatively little reliable documentation of American citizenship so the system adapted to that reality.
I tend towards being cautious with my information which has led to beauricracies doubting my existence.
I got my first passport at a formative period of my life (international travel does that). I looked nothing like the photo within aa year. It served as a passport until it expired but only created skeptisism as a photo ID.
I don't know how to drive, so do not possess a driver's licence. I am in a 35+ year relationship, but unmarried.
The only purchase I have made on finance was a bed that I immediately paid off because the the only reason I did it was to establish a record. This was surprisingly difficult to do because they were reluctant to let me have the bed on finance because I had no credit record.
I finally had to renew my passport when I bought a house. It was the only way I could meet the id requirements.
Prior to that I was leveraging non-photo id that could only be acquired with photo-id. It seen that will be accepted in lieu in many instances and allows you to get more similar forms of non-photo ID. All you need to get started is to find a staff member fed up with the ridiculous rules enough to click the checkbox to say that they saw a photo ID. It helps that many of the staff in these positions are more aware of security theater than the general public.
Being a land owner means a lot of those days are peassed, I can't really prove I am the person who is recorded as owning the land, but mostly organisatipns are happy that I am claiming to be someone they know exists.
Linkedin has stopped asking. I'm not sure if that means they think I am a lost cause or that anyone not on their books by now doesn't actually exist.
So for many years I only paid cash for everything, but I hit a point at which I wanted to start establishing credit. What I did was to open a secured credit card at my bank. They actually had me put it in a CD which was used to secure it. After I think 2 years of paying on time they removed the security requirement. I don’t know if that’s still a viable method but I used it in the early 2000s.
Yeah it's actually not that bad, because for example the BMV will likely upon request send you a duplicate driver's license to your address of record. Same for getting replacement credit cards. If you had utility services at that address in your name that's additional documentation. Also historical tax returns, bank accounts, etc.
"why's he asking for a new dl? "
"Oh volcano exploded, his home is under 5 ft of ash."
"Gotcha, mail him the copy"
Fun fact: If your house is under 5 ft of ash, it's not covered by volcano insurance. That only covers you if your home is destroyed by the actual eruption/explosion.
What you need is "pyroclastic event" insurance to cover you for ash and lahar.
/ It cost something like $15/year when I lived in Seattle.
// The macOS spell checker doesn't know "lahar."
This basically covers the financial model of the whole insurance industry;
Getting something like Volcano Insurance requires some specific foresight, I would be slapping myself on the back if my house was covered in volcanic ash right up to the point when I got on the phone to my insurance company to make a claim.Brb, gotta camp on top of the ash at the same lat/long coordinates to catch the mailman.
At least you can restore it. Imagine all your devices are lost in a massive fire, is there a way to get back your apple account?
I have a 'bootstrap' system... I have recovery codes and a backup for critical things encrypted and stored in a public git repo I push to both gitlab and github. If I lose everything, I can use those recovery codes to access the things I need to recover my digital identity.
Phone number and email access, if you can regain access to them.
It is definitely a good idea to plan in advance and set up a recovery contact: https://support.apple.com/en-us/102641
But email access is protected by MFA based on your destroyed device. Recovery codes are also stored in the same destroyed building.
You can get back your phone number once you have a photo ID and buy a new phone. Then you should hope that your service providers aren't secure enough to have disabled SMS-based account recovery.
If you're married and Jewish, the wife's mother keeps the marriage document, so even if there is a house fire and all documents are lost, your mother in law usually lives in another house, so you can pick it up from there.
I’m married and Jewish. It would be pretty surprising to me if my wife’s mother had even seen our marriage paperwork let alone possessed it. This also isn’t a tradition I’ve ever heard of in my family.
Or did a joke about overbearing mother in laws just go right over my head.
Ask your mother in law. At least in Israel, during the ceremony, the Rabi gives the ktuba to the bride's mother for safe keeping.
Sort of the plot of Banana Joe.
Everytime I get stuck with some kind of circular bureaucracy I shout "it's Banana Joe all over again!" and no one understands.
Hadn't heard of that one before. It's a Bud Spencer film!
And now I also know that he has a law degree, has several registered patents, and was a certified airline pilot. Pretty impressive.
Do the people who sign sworn affidavits already have to have proven identities? If so, then they're unable to recover from a situation where they lost everyone's identity.
In Austria, there is the concept of "Amtsbekanntheit", meaning if the government officer knows you, that's also valid proof of identity.
You start with the queen. Everyone knows who she is.
While in jest, It does remind me of the time Dolly Parton entered a Dolly Parton look alike contest and lost.
In fairness, she isn’t a Dolly Parton look-alike.
Yes exactly, I'm the queen, and so's my wife.
There is little alternative.
A great-great grandfather of mine was mayor of a town through which the front passed twice during WWI. All that survived were basements. Your father's account more or less describes the process by which the land was reparceled.
This is where "possession is 9/10ths of the law" comes from.
I actually think our discussion came from there! Or at least, there was a previous/later discussion about this exactly related to that.
It's one of those "programmer misconceptions" - we want to make reality fit our neat and tidy list of rules/laws/code; but it's the other way around most of the time.
There are also physical markers in the ground at the corners of most properties. So if you had to, you could send a surveyor out to recertify boundaries. That would get very expensive quickly, however.
This is not true anywhere I've lived, and I'm curious where it is true.
Generally, those markers are placed by the person who did the previous survey. They’re not really official designations of anything. However, if you look around, you will find things called survey monuments. Sometimes they’re embedded in the sidewalk, or the middle of the road. Out in the boonies sometimes there’s a little concrete pedestal that has the marker on it. Anytime you look at a recorded deed you will see a legal description of the land and generally that description will start from one of those monuments.
It's usually a piece of steel rebar/round stock or pipe, maybe with a yellow plastic cap, or maybe not. Usually buried or not very visible, I'd guess the surveyors find them with a metal detector.
This is true most places in the us. Have you looked? You often have to dig up the stake. It helps to have an idea of where it should be before you start digging.
Most of the us has it like that. Some of the early states still do 'nw to the stump', a stump that rotted away before 1800... The newer states learned that lesson and land is to something more likely to last and hard to move. Metal stakes are most common. Though most people are not aware of the stake since there is no reason to look for it.
They are commonly found by lawn mowers after some erosion.
I'm not aware of corner markers being the standard, at least in the central and western US. For rural and undeveloped land, oftentimes you can pay the surveyor extra to put up corner markers though, which is a good investment if you plan on fencing the property
Wouldn't work in a city like NYC where nobody knows their neighbours and a chunk of houses are empty and only owned by shady shell companies as investments...
Shady shell companies do an excellent job of proving ownership -- it's the only reason they exist! So if NYC is hit by an asteroid, you'll find backups of all the important papers neatly filed away in Delaware.
Not saying that this is the only reason, but it is a big reason why we have a land survey of our property on hand on paper and stored online. If something ever happened to the registry, we could at least establish our claim to our land.
Don't you have a land title, which of course is more evidence than a survey which anyone can pay for and get?
The title proves ownership (kinda), but does not define the outline of the property itself.
If the you need to know if the fence is on your property or the neighbor’s, a title or deed won’t help you find that line.
So if the official survey is lost and you need to know where the land you own is, you will need a survey.
Recorded deed will more or less universally contain a legal description of the land. This does, in fact, defined the illegal outline of the parcel.
A survey is little more than marching out into the field and putting at the location where you believe the boundaries to be based on your review of the legal description.
Of course that’s not the end of the discussion as to boundaries for reasons like adverse possession or busted titles but on his own a surveyor is going to tell you basically nothing.
Very place dependent and not so universal in my experience. Where I live the title/deed just has street address. A completely separate agency holds the plot map that links addresses to physical measurements.
Surveys, at least here and I assume everywhere, also contain parcel numbers, the neighbor's parcel numbers, and the legal owner of each parcel's name right on the survey. Along with the date of the survey. I live in a pretty rural area where 20 acres is a small lot, so having proof of where the property lines are tends to be just as important as the title.
I always wonder how things would be reconciled if something similar happened to a bank. What would be the simplest way to ‘download’ one’s balance whilst proving that the downloaded files were signed by the bank?
I'm good with starting from 0 if the bank is (my mortgage is a lot bigger than my balance)
Sods law would be the only bank not affected would be those I owe money to
Your best chance would probably be mailed statements
Your balance is at a bank. If the bank is gone your balance at it doesn't matter.
In my country, titles are always issued in duplicate. The land registry gets one of these originals, and the landowner the other. Just about every landowner has their original on their person, or held by a bank if it's mortgaged.
So all is not lost if the registry goes up in flames.
And this is why we need title insurance :(
Happened here about 30 years ago with a fire in a council planning office. All building plans and records were lost. It was enormously useful because there was no way to prove that that house addition there wasn't approved or in any plans. Fans of Yes Minister will know the appropriate quote from Sir Humphrey.
Remember the xerox-scandal years back, that invalidated officially scanned documents. You already life in a world where "scanned before" means you can legally challenge the validity of a document.
Is this the scandal to which you are referring?
https://www.bbc.com/news/technology-23588202
Yes, that is what they're referring to. The technical details behind it are kind of cool. It's a "bug" of the JBIG2 compression algorithm. See 1, 2
[1] https://community.apryse.com/t/jbig2-compression-issue/1814
[2] https://en.wikipedia.org/wiki/JBIG2#Character_substitution_e...
All I see is 1, 1
There‘s also a great conference talk [0] on this, with an english translation [1].
[0]: https://youtu.be/7FeqF1-Z1g0
[1]: https://youtu.be/zXXmhxbQ-hk
Yes, several national archives where affected on all settings. If a institution scanned and archived documents with these- these documents are - in theory challenge-able in court- within reason..
Hah, scan-dal.
I am pretty sure I was bitten by this bug, or a similar bug, on an IRA transfer form that I uploaded to a bank. On the scan that I uploaded, one digit in the account number was a clean "5", but the customer service person said it looked like a good clean "6". I presume their document management system was an outcropping of a system originally set up for dealing with faxes, and used that or a similar compression algorithm.
Thus - one could assume that all transfers stored by the bank- before the update would not hold up in court.
I don't know what you mean by "hold up in court". This seems to be an instance of software engineers making sweeping prognostications about legal matters.
"Hold up in court" as in was it duly executed and filed by a certain date, regardless of the time and extra management required for the bank's performance? Yes, why not.
"Hold up in court" against someone claiming it was an unauthorized transfer? Even without the bug, that can be contested in many straightforward ways!
But unless there is a specific legal claim that hinges on the bug being significant, it's pretty irrelevant "in court". I knew about this precisely because the transfer failed to go through due to redundancy - one digit in account numbers is generally a check digit, plus account titles and whatnot.
In general you can always challenge the validity of scanned documents, regardless of known software bugs or not! Just like you can always challenge that a paper document is a forgery. You need a specific argument and some evidence though!
The specific argument could be that the sum entered was falsified by the process digitalizing
One should assume the outcome of one's case in court is at least partially, if not heavily, influenced by one's political (influential-ness) standing.
I'd bet money the offline copy is far from up-to-date, given the state of the network. It still has potential to be mayhem
If its at least somewhat recent hopefully those affected still have paperwork for any property ownership transfers. Finding proof of property you bought decades ago would be a huge pain.
The problem is that everything will potentially be under dispute, since anyone can claim they purchased a patch of land whose registry was missed in the restoration
Don't know exactly on it works in Romania, but proving you purchased a patch of land is a different question -- for that you have the deed. You then submit the deed to the land registry. So this situation could at most result in the seller being able to sell the land more than once or disputes over the priority of sales over liens and other competing acts subject to registration.
The United States is rare. Most countries (seemingly including Romania[1]) have adopted either a cadastral/Torrens title system in which the land registry is definitive legal evidence of who owns a particular piece of land. If you purchased a piece of land and that wasn't recorded in the registry, you are SOL because registration is what conveys title.
The United States on the other hand has a massive title insurance industry, which wouldn't exist if this system was implemented. So you can make random handshake agreements all you'd like and sue over it.
[1] https://www.elra.eu/the-principles-underlying-the-land-regis...
Here in Brazil lots of people deal land by word of mouth. The country is just too big and there isn't enough state present to make every transaction official, so people shake on it, draft an unofficial document and actually living and developing the land over a long period of time is what consistitutes ownership.
It doesn't take much. A neighbor and I just had to deal with a bunch of property line confusions in the US where a property subdivision 25 years ago wasn't handled correctly. None of us really cared but it would matter in the event of an eventual sale and it cost thousands of dollars in surveyor and legal fees.
ADDED: We also had a bunch of easements and cooperative maintenance agreements that were only partially documented in the deed and mostly done via a handshake. So we got that all squared away in the expensive binder from the lawyer.
The public public land record in Croatia is notorious for being outdated and poorly maintained. Basically, the last time it was properly maintained was during Austria-Hungary a century ago, or at least that's the popular opinion. Right now we have the cadastre and the land registry and they do not always align. And for your example of unofficial agreements, the land my father and his brothers inherited is still in my grandfather's name, he died over 20 years ago, now my parents are aging, and there is just a verbal agreement on how the property is divided.
This is well documented in the the book "The Mystery of Capital" by Hernando de Soto. When it was published I thought it would change the world, but apparently nobody cared. :-)
In his thesis, this is the reason capitalism cannot work well in Latin America and other nations around the world. He says that registered land ownership is the foundation of capitalism. This is how one can borrow money against your land and invest it to make more capital. Very common for example with farmers in N. America to borrow against their farm, for machines, seeds and fertilizer.
(I am not an economist)
The reason capitalism cannot work well is that it assumes endless resources and infinite growth, not because people don't like electronic transfers. Capitalism is failing in all countries and those that are not are already transitioning to some form or another or post consumerism.
Sure at the "end game" stage you are correct. But on the way to that stage it does what it does really well, meaning it makes lots more capital.
De Soto is talking about why it "cannot" get started in a place without government controlled land registry.
> without government controlled land registry.
De Soto describes the exact opposite situation. Latin America inherited Napoleonic property law, which only recognized property ownership when formally registered, which required quite alot of red tape. It was impossible to transfer ownership without registration. Moreover, any defect in prior registration meant the lawful owner might be the heirs of someone generations ago. Most property "owned" by the peasantry usually had defective and incurable title, having changed hands in informal private agreements, which meant banks wouldn't accept it to secure a loan. This meant only the aristocracy could leverage the financial system, because they were accustomed to following all the formalities. What piece of real property someone thought they owned, even if occupied for generations, was often in the eyes of the law owned by some aristocratic family or the state.
He contrasted that system with the American common law system, where title could be legally transfered entirely privately. Disputes are handled by courts which look to the timing and substance of transfers. Moreover, adverse possession meant that after a number of years (well within one person's lifespan) nobody could come along and claim title because of a defective transfer (even if in principle they had a better claim originally), securing title in whomever held it, even if it had been transferred without even following the much looser requirements under the common law. A bank would issue a loan so long as you could prove you held an unchallenged title for a sufficient number of years. ("Title" was whatever piece of paper handed you by the previous possessors; no government stamp or recordation required.)
Registration systems in the US are a recent occurrence, and they overlay the traditional common law rules.
A gross generalization, but Napoleonic civil law systems emphasize formal transactions centrally administered by the state, while the common law emphasizes looking to the substance of private transactions, and usually only when a dispute arises (otherwise you just presume they're valid). Broadly speaking, De Soto argued the latter tended to favor the common man, because it was much less rigid.
De Soto also pointed out that US Federal Land Grants also did a decent job at distributing land among the people, unlike Latin America where mostly only the aristocracy held land under a good title.
Sorry to break it to you but we are past end game since possibly the dot-com bubble.
"Cannot work well" and "cannot get started" are two different things. The whole of Latin America apart from Cuba is capitalist, for better or worse, regardless of how bad those countries keep their books.
If De Soto is correct, and I am not qualified to judge, based on your statement about land ownership in Brazil, then capitalism was not fully developed to where it could have been. Get the book. It's an interesting read.
And yes I can see that we are at the end of an era. This may be more the end of the U.S. empire than the elimination of capitalism, but for sure a new 'ism" is going to be required soon. What that is will be interesting to see. It would be nice to see someone with imagination come along instead the bipolar options we are handed today.
That’s how it works in the US too. We don’t record documents with the county recorder to make them official, we do so to provide notice to third parties who might purchase the land.
You’re going to need more than just a claim to prove that, and anyone who did purchase land likely has some evidence in support, even if it’s testimony from others.
e.g. if you made a big buy there ought to be records of a bank transfer, mortgage, etc.
"i paid for 30 acres here at $xx rate, and here is the mortgage docs from the bank dated March 19th that I signed, plus their valuation of the property and what went into it"
Lots of land deals aren't dealt in money transfer either. It's sometimes cash, livestock transfer, other realstate or durable goods like cars or machinery.
Only if you bought between the backup date and today
(And obviously has some doc to prove it)
It depends. In my country the online land register data is just a copy of the physical land owning certificate. The physical certificates (1 for the owner, 1 for the local government, and at least 1 more for some document keeping agency) are the source of truth.
Quite likely the opposite: a few weeks ago a ransomware attack halted ~100 hospitals' management systems in Romania, and the cybercrime defense unit just disconnected all hospitals and had the local admins rebuild from backups and paper trails. So I'm quite sure that all public administration IT admins have been running drills and probably have up-to-date backups.
I'm skeptical that they not missing at least a week's or so worth of land title registry transactions, if the only thing they have left is offline, because offline backups are not made after every single transaction.
If the hacker was targeting the erasure of a particular recent transaction, they may well have succeeded. And by deleting numerous others, they have plausible deniability in the subsequent dispute over the property. If you just wipe a record that is related to you, and the manipulation is discovered (which it will be, one way or another), you are part of a narrow circle of suspects.
> offline backups are not made after every single transaction.
All you need is an append only tape or even a printer.
Interestingly in the Bangladesh Central Bank hack they used a printer to print out any transactions, but the intruders disabled it or it was just malfunctioning because it's a printer.
But I doubt the Romanians actually had such a system.
In such case notaries (or whoever reports transaction) can resubmit them.
Also, you still have paper documents, kept by parties to transaction, right?
When I worked at a stressful place I was worried not only of our version control getting damaged but also someone deciding they had had enough and doing damage on their way out.
I had a copy of our code on media in my desk labeled “promotion” and updated it every month. In retrospect someone going through my desk would have assumed blackmail material and been disappointed to find only code.
I wonder why the say "appears to have had," is that an assumption or was it stated somewhere? Without an offline backup, it would indeed be a very serious problem, more than it already is.
My reading is: "The agency would surely be panicking more than this if they didn't have an offline backup".
"Offline backup", as in "thousands of shelves full of dusty binders spread across offices all over the country"?
Yup. Everyone’s job safe for the next few years!
"And to think that we just finished digitizing all those paper files five years ago! Oh well, back to square one..."
I think the "offline" part is what is that "appears" to be, clearly they have backups somewhere, but maybe the attacker just missed to wipe some other "online" location.
I interpreted this as a vagueness related to the reporting accuracy, not the existence of a backup.
> the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months
The last thing any government will want to deal with is massive irretrievable data loss.
https://www.youtube.com/watch?v=K_FrQnQv0Vw
now they get to do a greenfield implementation too!
/joking, i'm sure this is not a happy time for whoever is trying to rebuild everything
i think it is a very happy time charging whatever per hour you want
Has not digital data always been a secondary source of information, instead of a primary source of information? Paper records cannot be thrown away. And new records are probably recorded digital only but a copy is sent to the parties in the transaction
At least in my EU country, no the digital record is the primary.
When you buy property you get a deed for the land, but the details of a property can change after that. The deed also doesn't contain ownership, it just says what is on the land. It's common for land to have multiple owners (1/32 is not unheard of) due to inheritance.
I'm building a house, the land deed just has the land plot as we bought it, until the house is 100% finished (and registered) we will not get an updated deed, although the digital system has newer data (you need to register the construction progress).
In the UK deeds no longer really exist and do not take precedence over the land registry.
Property that isn't registered can remain unregistered but must be registered before it is sold.
Paper records burn great and are harder to store in multiple locations
They're also often stored in basements, which is the first to flood.
Faxes and photocopiers have existed for nearly a century
A photocopy isn't a primary record!
OK but the primary record itself is not the primary record when challenged in court; subject to a change order; redefined by legislation or handled in many other ways. There is money involved.
Any country big enough was moving digital first/digital only for years. And with a paper records there is always a question if this one is the last one and contains a valid data or it's from years ago and since then everything was changed multiple times.
Just recently I've seen a 30 y.o. deed on some commercial property. Despite it was valid and predated the digital era, it had almost nothing common with the things on the ground.
> I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
You know, it's not like people would come and steal your land overnight because you can't provide proof of ownership.
Squatters, boundary disputes and rent defaults happen all the time.
Plus having most of your net worth locked up in something no sane person would consider buying off you because you can't prove you own it is ... suboptimal
People can come and cut down trees, use the land for their cattle, raise crops or just start building something. If you don't challenge it and they get away with it for a while, they could even gain use of the land legally.
Happens far more often than you would think in developing countries.
Property lines disputes happen every single day in America, too. It's a universal thing.
After the tsunami that hit Thailand and wiped out many fishing villages on the Pacific coast, the people were evacuated but as soon as they returned, they found the local mafia occupying the land, and as they had no need and there was no land registry, they were forced to rebuy their land.
https://www.bbc.co.uk/news/articles/ckg15ev0347o
"Under normal circumstances, property law in England and Wales dictates the original owner cannot claim their property back even if the title change was made fraudulently."
That's... a curious thing to have in the body of laws. What's its purpose and who does it serve?
In the US, real estate purchases come with "title insurance", because there is no official, guaranteed, land registry database.
That depends on the state, some do have a registry.
wtf
That’s a simplified explanation. Title insurance covers a number of situations, fraudulent transfer of title is only one of them and is more likely to be something like “A wife sold her dead spouse’s house, but it turns out that there was a dispute about the will and now someone else is claiming that the house actually wasn’t hers to sell”
That wouldn't be possible in my country because she would not have any right to sell the house until it was transferred to her. This transfer would happen during the probate process. The probate process is where all issues regarding the will/estate and disputes are settled. Once probate is complete, ownership is set in stone and the widow would have every right to sell her house.
The sad part is, the whole world worked perfectly fine without anything online, ever, prior to 20 years ago. Even 10 years ago for slow-moving change.
It's literally not a requirement to have it all online. And the cost of developers, plus coding + security updates + platform costs, really just means you replace a few assistants which would process requests by hand, with all that.
Except? It's a lot harder to hack a person to delete all the files in the office, from 10k km away, than via a computer.
So many things simply don't need to be online. So many things simply are better archived by other means. So many things are safer, more secure, and the backup processes (microfiche, etc) are well understood and just work.
There are many examples of important paper records (property, birth/death, etc) being lost in fires or floods, so it's not the case that "everything worked perfectly fine" in those days either.
All those examples are not different from not having backups of digital data too. Making copies when you microfiche, having duplicate stores, it's all exceptionally easy and a solved problem.
And of course everything didn't work perfectly, it did however work "perfectly fine", which means "very well" or "good enough". Meanwhile, adding in network connectivity to anything vital these days is just insanely dumb.
No software is secure, and will never ever be secure. Ever. Anyone who thinks that software can be made secure, is 100% wrong, period. My point is that the advantages aren't worth the disadvantages.
Your overall assessment of advantages and disadvantages seems like you're comparing paper with backups to software without backups, though. No competent system can have all the records destroyed remotely. And we know how to backup digital systems even better than we know how to backup paper ones.
And as a third option we can have efficient digital systems that aren't plugged into the Internet. (Presumably the Internet could have a copy that's regularly updated.)
I was ready to argue until I got to the end "My point is that the advantages aren't worth the disadvantages."
Suddenly your entire argument shifted in my head and I fully agree.
Might be something there I can learn about myself then :D
I agree that digitalization is not a panacea, but things did not work anywhere close to perfectly fine when everything was on paper. There are just as many ways for analog/physical processes to go wrong.
A sophisticated genius hacker in a different country can’t touch your paper records, but an absolute moron with a bic lighter can destroy records just as effectively. Hell, an irresponsible clerk can do an incredible amount of damage just by misfiling things.
Duplication literally doubles costs in the physical world, and has the downside of being very hard to keep in sync. A bank keeping paper ledgers would be absolutely fucked if they had to switch to a backup ledger that was more than a few hours old.
On net, I believe that digitalized documents are a net improvement.
Yeah, while online copies are a risk, you can make offline digital copies of important data for a thousandth the price of paper copies.
Put some desktop-size tape robots in several government building closets, and task someone with switching tapes weekly, and you can achieve more reliability than multiple huge paper archives.
Yeah, we’re early culturewise in the digitization experiment and high on optimism about the benefits, but not very far into reckoning with the downsides and incentives skew a bit towards carelessness.
The real danger is that we’ll be so careless we’ll discard other enduring ways of doing things before we smarten up to their particular benefits.
My hope is that disciplined people still have an intuition for this, even among the digitally steeped. Sysadmin/ops types tend to a culture of diversifying backup location and even media type. Maybe that can reach back to human legible hard copy.
Everything comes with a risk, and people usually take it with a decent understanding of how to mitigate it mostly.
If we start thinking along the lines of technology has risk and we shouldn't use it, we should go back all the way to the discovery of fire as we all know fire can cause a lot of damage if in the wrong hands.
Technology can make lives safer. However, software is never secure, cannot be made secure, this is empirically proven to be a 100% valid position.
In as software is not secure, and can not be made secure, using it for important records storage makes zero sense, unless you a) have full backups offline in physical, non-digital, read only medium or b) just don't do it online, at all.
And my point is, it's not worth the convenience.
But physical records also cannot be made secure. And the convenience is gigantic. I think that it is worth it, as clearly does much of the world.
Read the scope I discussed. Physical records can be made exceptionally secure. They can be secure on location (archival location, with guards). They also aren't reachable by every human being on the planet who wants to infiltrate.
Think about it. To destroy the public archives, of which there is typically more than one, you must travel to said location, breach it with weapons and other means, and destroy it. Or, you can sit in your parent's basement in your pajama's, and hack and destroy.
There is not even remotely the same risk profile.
And if you think something is "good" because 'the world thinks it is good', then I have to ask you why you're validating something via popularity. You know what else was popular? Fossil fuels. Smoking. Using uranium in makeup for women. Something being accepted, and being fun or convenient, doesn't make it correct, sensible, or right.
So please describe the horrible and incredible "gigantic convenience". Because I lived before the internet, and now after, and yes it is convenient.
But it certainly isn't a 'gigantic' one, nor is it sensible compared to the insane attack surface and risk.
A land title is written on paper or cardboard, with signatures and stamps on it.
The digital copy is just that; a digital copy.
The hacker would have to destroy the database and all backups, and also burn down the building holding the registry.
That's not how things work in most countries in Europe: the land registry is the authoritative source, and there are no bearer titles any more.
Romania is not very digitalized, and it still has a lot of paper bureaucracy.
Even if the digital records were completely lost, they still have the paper ones.
> being unable to prove land ownership
People know who owns what, there are also paper contracts of ownership which are more authoritative than the digital records.
> the societal implications of being unable to prove land ownership
accidental communism
One more reason to to define the whole infrastructure in code and have offline backups. Recovering could be measured in hours.
A backup that isn't offline is not really a backup as it far too easy to destroy it even by accident/carelessness/lack of understanding.
When I was responsible for backups we kept the tape cartridges in a fire safe in a different building. We took a full backup weekly and moved the tape from the robot to the firesafe as soon as the backup was complete. Only the daily incremental backups stayed in the robot for more than a day.
> has entire infra in code
> spinning up a new shard takes a quarter
Both can be true
That sounds good, but wouldn’t you worry that the same hackers will let themselves in via the same route again?
You would need to understand first how they gained access and verify that they can’t do the same again. That in itself could take days if not weeks. Then of course they might have found new vulnerabilities while they were in, so you would need to worry about that too.
Only if you routinely test it, and if that kind of access to the offline backup is low friction enough to be doing that monthly, it might not be enough of a redundancy.
> Recovering could be measured in hours.
Yes, even hundreds of them sometimes.
The most time consuming part of recovering from an attack is validating everything. It takes more than a few hours to validate the infra that stays put isn’t compromised, the IaC code itself isn’t compromised, deploy the infra, bring a copy of the offline backup of your data (your IaC can’t drive to another site and bring the backups, then make a copy, unless tou are really sure you removed any trace of compromise), validate that the backup is sound, then restore it.
In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.
> The most time consuming part of recovering from an attack is validating everything. It takes more than a few hours to validate the infra that stays put isn’t compromised, the IaC code itself isn’t compromised, deploy the infra, bring a copy of the offline backup of your data (your IaC can’t drive to another site and bring the backups, then make a copy, unless tou are really sure you removed any trace of compromise), validate that the backup is sound, then restore it.
> In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.
Your IaC is supposed to be on those offline backups too, and should be able to do everything from clean hardware.
The most time consuming part is to identify what caused the compromise. After that, you can put everything back online and then at the same time start to analyse who did it/what they did and so on. If the root cause for the breach is identified, you also know the time most likely and can trust the offline IaC backup.
An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):
ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.
After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.
ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.
According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.
The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.
The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
My ex was late from work once a week because the company did commercial real estate logistics (sort of similar domain here) and she had the job of going to the secure data center and grabbing a backup disk out of the cage and transferring it to a safety deposit box.
The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or all three. The owner kept a second copy at his house, and that was the only geographically separated copy.
>it had begun migrating its applications to Romania’s Government Cloud
This proclamation, coming from a governmental organization, makes me afraid they are doomed. Effectively they are saying they are fixing the mistake by repeating it.
What they should do is admit fault. Freeze the system. Get independent expert help.
Best wishes, recent Romanian land buyers and sellers
Edit: thank you @cbg0 for giving us this update
They are getting expert help. I expect that the agency maintained their own local deployment on infra administered by its own employees. Now they are migrating to the central 'government(-maintained) cloud'.
At the same time they are working with authorities.
Not everything needs an external consultant.
Your prejudice knows no bounds.
Romanian friends have told me that this is really due to corruption.
Specifically:
- government gives IT/data contracts to cronies
- cronies don't actually do any real security work to protect the data
- things like this happen
As a Romanian I can tell you that most of the corruption happens through "dedicated contracts", or outright syphoning.
In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.
If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.
If it is any consolation, this kind of corruption exists in many countries. I don’t know how to fix this, but corruption always finds creative ways.
Here is one I learned recently - govt started issuing birth certificates online. Hopefully Less corruption, right? Officials made deliberate spelling mistakes in names etc, because you have to go in person for corrections. In person means bribe, which means back to same situation as before (almost)
Same thing is rampant in other Eastern European countries as well. Tips on how to address this for those of us that are publicly minded?
It's no different anywhere. Security isn't valued since it's just an email and a .01% or less income fine.
The amount of times my SSN and correlated info has been leaked and I've been offered a free year or credit monitoring is depressing.
Problem really is that things like SSN or ID numbers should have never been treated as more as just one possible semi-public unique identifier. Never anything to be used in identifying a person for a contract.
This would implicate close to 100% of American firms and most of the adult population?
If they are clearly misusing a system (SSN) never designed nor intended that way. And continue to do so even after being shown the facts.
There is a somewhat valid argument to be made that aggressively trying to hack these insecure government portals could lead to a real reprioritization towards competence.
I'd say form an IT firm and bid on government contracts and do honest work, but we all know how that goes in reality. Honest workers don't get the contracts. You can still try, though.
I'm sure it's obvious to anyone living in a corrupt/oppressive regime, but in case it's not obvious to everyone.
Corruption and oppression are signaling and coordination problems. The illegitimate sovereign is exploiting informational assymmetry: they know your neighbors are just as angry as you, they know it because all the walls have ears.
They need to prevent you and your neighbors all knowing it at the same time. Your best play is to find some signal, something difficult to censure, hard for the goons to pick out in a crowd but legible to your neighbors. If you all knew that the first guy to shove back when the cop shoves you is going to be followed by a swarm of guys? Very easy to find the first guy in that case.
This is why shit like extremely high gas prices scares the shit out of illegitimate sovereigns: they're the ones posting pure data about why everyone should be that angry right now.
Vote and join a party
Look at what the new Hungary PM is doing
Use EU funds to build it then tip the EPPO when they defraud the funds?
Somebody vibed an explainer dashboard with what surfaced online about the incident https://ancpi-atac.mariuscomper.uk/en/
It is not corruption. Or not just corruption.
A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
They said this in the article:
> Sources told Risky Business that the hacker entered using valid credentials
This is the same in the UK too. Governments everywhere are the same. It's just humans motivated by greed and easily corruptible.
"It's corruption and cronies" is a generic cop-out answer that doesn't explain anything.
Like whenever someone gets caught in a compromising situation they say they "were hacked", as if saying that means anything.
Its a bit more nuanced than that. The company responsible for ensuring the cybersecurity of the system told the press that "they secured what the client told them to secure and it was not their job to tell the client what needs to be secured".
And I think it's a label that's used freely on Hacker News against Eastern Europeans
It's always amusing how this is always attributed to the corruption.
It's even more funny on Reddit when you can see the person who is blaming cronies in his Romania but has posts of him doing some blue-collar work in the Midwest.
Algeria has a extradition treaty with Romania:
https://periodicos.processus.com.br/index.php/egjf/article/v...
Or just have Opsec.
Well, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit too
Tangentially reminds me of what happened to the South Korean gov data center [1] where a no-backup ~900TB data center got erased due to a battery fire.
Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.
Last i heard i think they had restored a quarter of the lost services/data.
[1] https://www.intermediagroup.org/south-korea-data-loss/
The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.
That was my thought exactly on reading that line: that is not a backup. (Ok, the word isn't strictly defined, but you know what I mean.) They have said there's a "real" (offline) backup as well, luckily, but that just reinforces that the "pretend" backup was irrelevant and wasn't even worth mentioning in the writeup.
Any guidelines on how to back up such that the attacker cannot reach (when the hacker otherwise had some valid credentials)?
This is how we implemented this at our company:
- We have 2 sources of data that we must backup to continue existing as a business; our postgres and binary files in S3. Everything else is derivable (elasticsearch, so on).
- For postgres, we use barman. With the help of opus/fable, you can get a streaming replication backup working in no time. We have one into another server in the same datacenter (we use baremetal) and another one in another server in a different datacenter.
- We then have a last resort barman backup with bi-weekly base backups + WAL streaming to S3 (both the base backup and WALs). It sends these backups + wal segments into an specific S3 bucket that has object lock in compliance mode. This is a feature from AWS S3 that even the most privileged account credentials (super admin) can't turn off nor delete the files before the object lock, which is 10 days in our case. Object lock compliance mode can only be extended, never shortened.
- For S3, we store them into another versioned bucket, with lifecycle rules to also expire non current versions (== deleted objects) after 10 days. No point in object lock compliance here because it would only protect objects for the most recent 10 days, and you gain nothing. What we do instead: the app servers only have access to these bucket tru an IAM credential that can't delete old versions (so deleted objects have to expire manually via the lifecycle rule) AND this IAM credentials also can't change the object policy.
IMHO, this protects us enough so that even in the worst case scenario (ransomware) we have 10 days to sort everything out and recover our AWS access.
And yes, we test the S3 barman restoration and it works fine. Data loss is at max 5 minutes due to the archive_timeout=300s on the primary.
For the streaming replications in the two servers I mentioned, it's less <1ms, but those wouldn't protect us much in the case of the ransomware - even tough we use tailscale and one compromised server can't ssh into the other.
The same thing happened to Slovakia not that long ago.
The Slovak land register was hacked in January 2025. Hackers uknown encrypted the database, asking for an undisclosed 7-figure amount as ransom.
The whole country's real estate market was paralyzed for about a month. It took couple of months to restore everything from backups and paper agenda and resume normal operation of the land register office.
It was the largest cyber attack in Slovakia's history. The authorities to this day haven't provided any information on who might be behind it. The investigation is still ongoing. Several government figures including the PM were however very eager to immediately point on Ukraine, without any sort of proof.
If I remember correctly, this is the hack that Fico tried to blame on Ukraine, even if the hackers were a known Russian ransomware crew that literally posted in their Telegrams about their support for Russia... right?
Accounts at the time:
"1T+ in assets are frozen as Slovakia's Land Registry faces ransomware attack" <https://spectator.sme.sk/politics-and-society/c/news-digest-...> (9 Jan 2025) HN discussion (1 comment): <https://news.ycombinator.com/item?id=42650343>
"Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations" <https://dailysecurityreview.com/security-spotlight/slovakian...> (January 14, 2025)
"Slovakia Hit by Historic Cyber-Attack on Land Registry " <https://www.infosecurity-magazine.com/news/slovakia-hit-by-l...> (10 January 2025)
Apparently tied to Ukraine in this case.
> Apparently tied to Ukraine in this case.
Lord no! That accusation doesn't pass the sniff test.
Try looking further east for the real culprits.
Ukraine was specifically mentioned in two of the articles I'd referenced, though not in the one originally submitted to HN. I was dubious finding it once, hedged with "apparently" based on the 2nd. I did look for a Wikipedia article on the event which might have included a more substantive and reflective post mortem but didn't find one.
If you've specific information clearing or establishing the link, post it. I agree that hasty accusations are risky. The main point I was looking to establish was that the source wasn't indicated as Algerian, as with the Romanian incident.
NSA is west …
how did they solve it?
it took months to go back fully online. they also had usable backups (so they used those for the data), but the infrastructure had so many vulnerabilities that they had to fix it first, hence the delay
Restored from very old backups and paper documents.
"Very old" could mean that they were not up to date. What did they do when the backups didn't match the actual situation at the time of the breach?
You do a comparison with the up to date papers. It just takes ages.
The involved parties and the notaries keep copies of every transaction.
Property is not fluid and doesn't change hands very often. Sure, in a large enough market lots of activity happens every day, but any given property is only involved in a transaction once a decade. You can have very old backups and still capture the state of the market to 99%+. Any recent activity will have brokers, buyers, and sellers, who all have current copies of their activity.
Also, this sort of event should result in some hackers being found and jailed for life as well as their families being bankrupted permanently. Or, if they are being protected by their government, this should be considered an act of war and an appropriate military response should be delivered.
> as well as their families being bankrupted permanently
No one thinks bills of attainder are a good idea.
This wouldn't be a bill of attainder, it's simply an infinite assessment against the criminal's estate that can't be discharged in bankruptcy. I don't personally think that people should inherit their predecessor's debts, but I have no problem with debts being able to capture the entirety of a person's wealth including homes, pensions, jewelry, trusts, any accounts from which benefit is drawn, etc.
Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.
Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:
<https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>
<https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>
Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.
NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.
For me the first 2FA devices I’d had were for work but for my friends it was for a world of Warcraft. And it was years until my bank offered 2FA. I still think about that every time there is a breach.
Blizzard gave hardware tokens out to the entire convention one year. Smart phones became a variable not long after and then they didn’t make them mandatory but game guilds almost universally did. Especially for officers.
The UK used to have a distributed system - everyone had to have a solicitor store "deeds" of their property, which were a sort of paper blockchain of all the transactions the land had been in since - I don't know, since records began I guess. Since we got a centralised land registry cheaper solicitors have binned these, but some properties still have them as a historical record.
> since records began I guess
Possibly since 1086
https://en.wikipedia.org/wiki/Domesday_Book
You’ll see this as a plot device in some Regency pieces. Someone gets ahold of the physical deed to a property and now there’s drama.
Not sure what you mean by 'binned'. In some Common Law jurisdictions the deed document represents the property and whoever psychically holds of the deed controls the property. Any centralized recording system merely records the last known status of the deed and additional information such as the nominal owner, mortgage holders, etc.
Not sure if by "centralised recording" you are referring to the UK way or how it is implemented in general (civil law) but I can say that in Brazil the registry definitely does not have only the last deed.
In Brazil the books are append-only, they have the whole history of thay piece of land since records began. If it was a bigger plot that was dismembered, it is there too. When ownership changes you have to register the contract/terms of transfer/sale separately in a different process, but that does not change legal ownership and you still must go to the registry and register that registered transfer/sale in the registry, and the paperwork you get is a new certificate of registration which is a new snapshot of the books and includes that whole history from the very beginning. There is no copy or certificate you can can get from the land registry without including that whole history.
In the UK, the old common law rule does not apply to land that has been registered centrally, that is then the legal definition of who owns the property. However there are still properties that are not registered and for those, the rule you describe is still applicable; the holder of the deeds is the owner.
Registration is now compulsory on sales, but that only came in in 1990.
As to what I mean by binned, I mean literally binned, thrown away.
Offline and pull based backups FTW... This is why I advocate for a pull or at least push/pull model for backups... where the remote system pulls backups out of your production environment, or otherwise from a drop point. Because a corrupt production system that controls backups can corrupt backups.
If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups from there, you can better ensure older backup files are intact. More so by not allowing the two to see each other at all and not using backup accounts from a system that can access production resources.
Under the Australian Torrens title system, paper is no longer authoritative and if you bring a deceased estate title document to the registry they keep it after updating the titles registry database, unless you ask to get it back and it's stamped to mark it superseded. I know because I've done this journey.
3 2 1 people.
The majority of people have paper documents from the land registry. Digitalization of the land registry is a fairly recent development in Romania so people almost always requests papers when they register their land. In the event that all the digital data or large parts if were lost it would be possible to reconstruct it from the papers and interpolate the missing parts if any.
Centralized tech is an evolutionary dead end and all who attempt it will continue to learn the same lessons.
> HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models.
This, to me, is the more interesting bit of the article.
I don't really know what a good solution looks like, but yeah, that's annoying.
Why not just change ownership then? I'd bet some people would be interested to pay some money for that...
Imagine if the hacker was more clever and started writing plausible nonsense into the database, corrupting the backups.
Selling properties you don't own, ideally land owned by government..
ideally properties of corrupt politicians
Imagine all the times this has already occurred somewhere in the world.
This is Government, "plausible nonsense" is already being inserted into every single table on a daily basis.
we spent centuries building a system to track who owns what land and then put the whole thing in one database that can be deleted with a single compromised password
arte.tv released a documentary about measuring and registering land just a month ago @ https://www.youtube.com/watch?v=fl7AfiJs5Gk (Romania: The Unmeasured Land | ARTE.tv Documentary)
Enterprise storage arrays have immutable snapshot functionality that makes ransomware easy to recover from.
What does it take to delete a snapshot?
Depends on the vendor. Some just admin access to the array, other require a two person authorization to delete it.
local admin credentials or two factor or the BEST is a immutable time-lock, so a snapshot cannot be deleted before the retention period that was set when it was taken expires
What's wrong with an old fashioned paper registry then?
Rotting, sweaty human hands and fire to name a few.
Pretty sure fire is a risk to servers as well.
Servers make it easier to keep & maintain duplicate data in separate locations, which’ll be unlikely to be affected by the same fire.
only in that location.
mirror that DB onto a server on the other side of the country, or continent, etc.
Nothing, this is why they have both.
It isn't fast enough for mortgage backed securities. Each transfer of ownership of the mortgage requires a separate transfer fee paid to the registry.
Moving from a paper registry at each county clerk (in the US) was a part of the 2008 financial meltdown.
I am pretty sure they have that too.
So which one is the ground truth if there is a difference between them?
The paper rules supreme in Romanian bureaucracy.
As it should.
fires? floods? documents getting lost/misplaced/stolen/destroyed?
Seems to be rather sturdy in my experience. Would we even be able to read an electronic record after 100 or 200 years of storage? Old piece of paper is quite accessible.
Documents getting lost/misplaced/stolen/destroyed is common in some places (owing to corruption or what). "Local in scope" but rampant. Digitization has been a panacea as there is more control over the records, but now more prone to hacking.
> Old piece of paper is quite accessible
If stored properly.
So are digital copies, though. If stored properly.
You need a machine (hardware and software) to read digital copies, not just the digital copies.
And you need to know how to read to read paper copies. Same thing, essentially. Anyone speaking hieroglyphics fluently? Point is, if you take care of your archive and make sure it remains accessible, it doesn't really matter whether it's digital or analog.
Not at all the same thing - what equipment do you need to read hieroglyphs on top of understanding the language (which goes for digital, too)? If you have the paper and understand the language, that's it. We already can see that accessing old digital data isn't necessarily easy if it wasn't always kept on/converted to current media and formats (will we keep that up for millenia)?
And both storage can be broken, needing reconstruction.
If I were to give you a 70y old book in English vs some 70y tape with data on - which one is easier to read?
For the third time: IF you take care of the data, it’s fine in both cases. If you neglect your beloved book for 70 years and store it under a bridge, it’s going to be completely useless as well. The key part is the taking care of your medium.
The taking care of the book for 70y does not involve recreating the book over and over again to keep it readable or keeping a reading machine in working condition (or be able to recreate it). It's an entirely different level of care.
If the medium isn't destroyed, it is directly readable if it's a book, but not necessarily so in digital because hardware and software is needed - just taking care of the original medium isn't enough in digital over centuries.
There have been plenty of instances of paper-based land registries being wiped out. It's just usually a very local problem because paper lends itself more to decentralized storage
Yes, so quite limited in scope. We have no experience with storing and keeping accessible electronic records for hundreds of years, though, but we know already that accessing old storage media and formats isn't necessarily easy.
So far accessing old storage media from 50+ years ago hasn't really been a problem. Reading old tapes and punch cards/tapes or even early hard drives is something that a single motivated hobbyist can achieve in a few weeks or months with a microcontroller and patience.
But it's more difficult to imagine that 1000 years from now someone will be able to read from a PCI-E NVME drive if the specs get lost along the way (ignoring for a moment that flash storage most likely won't retain data that long).
I would not call needing weeks or months not a problem (assuming you also get the potentially proprietary software to understand the data recovered). Also, early hard drives weigh 100s of kilograms, so just physically handling them is difficult.
Totally agree on accessing NVME example.
Seems like fires and floods would also affect servers too.
Who was there first?
Dibs on Vlad's castle
would blockchain could have prevented it ?
No.
aka tokenize everything
Many many times, entire armies have been sent in to adjust another country's land registry.
I know people flip out when they hear the word crypto but this is exactly why you need blockchain. immutable land registry thats public(anonymized).
Why is deleting the whole database a valid operation? The system should make that impossible.
Hackers would do it from the operating system level - stop the database executable, then delete the files used to store the database. Likewise, many organizations store the backups on a network share, where a hacker could delete the files.
Permissions inside the database should be segregated. The credential used by the webserver should not have enough permissions to DROP DATABASE. Just the appropriate selects/updates/inserts.
Likewise, if you are storing backups on the same network (as opposed to a tape backup), network permissions should allow writes/creates but not deletes.
Why is deleting a row in a table a valid operation? Why is deleting a table in a schema a valid operation? Most likely they had full privileged access to the database.
>had full privileged access to the database
Why does full access include the ability to delete read only data that should never ever be deleted for the rest of time?
It's like building a self destruct button that ignites the physical records. It's an unnecessary risk to make such a dangerous thing.
Well, you don't understand databases. Or software.
I understand that many software projects don't understand the principle of least privilege and make god users that can do anything including deleting everything.
Incompetent bureaucrats strike again.
News at 11.
We will see a lot of those with open source Mythos equivalent models.
The new world will be: move fast and trust AIs
I mean:
> Sources told Risky Business that the hacker entered using valid credentials
This is social engineering or corruption.
... and an incorrect password policy and poor access control. Usually, in these institutions, if STS is not responsible, there are third-party companies, usually proxies, that are responsible for managing the firewall and accessing the data. The lack of procedures and lack of supervision from the authority, combined with the delay from the service providers, leads to a situation where everyone does backups as they think is best. That's why it takes so long now, because STS restores data from different formats, from different places, made at different times
“This is good for AI”
[Fairly off-topic and political]
There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.
Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).
It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)
The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.
As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).
I don't think that most competent IT people are pushing for digital-only systems. The people that I see pushing for digitalization are either clueless politicians or corrupt or incompetent IT people selling snake oil. The sad part is that the snake oil sellers are probably a majority already, so fighting against politicians and snake oil sellers is a tought one.
Amateurs. Everybody knows you should never wipe databases. You should install a cronjob that makes a random, unrecoverable change on a regular (but random) basis.
Seems like property ownership histories could be one of the few good applications of blockchain technology.
Was hoping it was a political act in favor of land reform or against owning property.
We had that almost 80 years ago for a few decades, but we shot a guy at the end of it. I hope the next one to suggest something like this remembers the history and refrains from it.
It did help the West, and especially the UK, to get as immigrants very high good plumbers and handy men. The rest of us went into STEM and are now working for FAANGS.
"you will own nothing and be happy"..no thank you!
Fair enough. But you do realize that all ownership is a made-up shared fiction that most people believe as real.
As long as trying to break that fiction has real-world consequences like jail time etc., it will work anyway.
That is sufficient to make it real for most intents and purposes.
Why is this skeptical property anti-realism useful? This argument obviously proves too much.
I always thought the “you will own nothing” expression referred to a Gini coefficient of 1, not 0.
The intent of abolishing private property would presumably be the latter.
Capitalists say "you will own nothing" and want a Gini coefficient of 1. Communists don't say "you will own nothing" - they say "abolish private property" and refer to a Gini coefficient of 0.
communists really say "social ownership of the means of production"
Depends on if you're scaremongering about Capitalists or Commies.
That’s true. But in a world with monthly toothbrush subscriptions one of those end states feels much closer than the other.
Romania already tried communism. The people did not love it.
Finally, AI is giving us some real-world blockchain use cases (assuming the attack was helped by AI). Only half joking, BFT is petty much the most adversary-proof security guarantee we can get in a distributed system.
So that 50% attack results in someone taking all the land? No thanks.
It is a poor idea to use blockchain for government registries. If you want transparency, simply publish signed daily updates and that's enough. Just use simple DB with backups, and optionally, a printer printing changes on a paper.
Merkel tree audit log of the data, the poor man's Blockchain, works fine and good enough. Now you have a db and you can claim to use a blockchain for pr reasons.
2/3 attack. Read up on BFT.
It doesn't matter, it's a dumb idea anyway because there is a central authority managing the land registry and there is no need for anyone else to be involved.
Also, SQL database is much more convenient to use, it has query language and indices unlike a blockchain.
You can put an index on your blockchain DB, what are you talking? Every node can manage it as it pleases (within the limits of the consensus algorithm).
Yes, if you have a centralized model you don't need it. Just saying that this incident is the exact risk a blockchain is meant to mitigate through redundancy. You can say you don't care about this risk, but it doesn't change the truth of the statement.
Yeah, the overwhelming majority of the benefit of blockchain here is just gotten by making the data public and signed.
Now you may argue "that is a blockchain, not every blockchain is associated with a shitcoin" but to be frank that ship has sailed, if you wanted to defend that you'd have had to do a lot more work over the past decade.
Which could easily be solved by just making data publicly accessible. Actually I see no reason why you shouldn't be able to download land registry say every month. Same actually goes for any stock ownership in companies over certain threshold.
That is what I'm saying. And you may be right, but the security guarantees are math and math is patient. If people decide to ignore it today, it'll still be true any time they decide to take another look.
>Now you may argue "that is a blockchain, not every blockchain is associated with a shitcoin" but to be frank that ship has sailed, if you wanted to defend that you'd have had to do a lot more work over the past decade.
What do you mean by "More Work" here?
There were plenty of tests and pilots of systems like that described. Dual goals of reducing the cost of transferring property and publicly attesting all current ownership. Real lawyers and real lawmakers developed proposals to integrate these sort of services with current public land registries.
The issue as far as I see it isnt the "work" its the "antiwork". If you want to learn about land sale nft pilots you literally have to put -metaverse into the google search to weed out the metaverse nonsense. Theres just too much noise around blockchain for even the best signal to penetrate. The stupid monkey nft guys really fucked the whole space. Probably take another decade to dig out all the toxic waste from blockchains reputation.
> It is a poor idea to use blockchain for government registries. If you want transparency, simply publish signed daily updates and that's enough.
A blockchain is essentially that, just with the daily update that's being signed also including the signature and hash of the previous day.
Blockchain as a technology is actually useful here. It does not mean automatically that blocks have to be mined by third parties, although pseudocurrencies have gone that route for decentralization reasons.
Blockchain is unnecessary complicated, for example, it has mining, rewards for those who add new records, even VM and scripts and all of these are not needed for a government registry. I do not need scripts within a land registry.
> Blockchain is unnecessary complicated, for example, it has mining
depends on configuration, you can make any traditional web service replicated (replication is one and only thing that protects data in decentralized ledger, same as DNA is stored in every cell) using something like CometBFT on top. Mining/PoS or VM - all optional.
Clearly, you would scope the features and choose implementation options so that it makes sense for the use case. Mining (ie PoW and/or Nakamoto consensus) is clearly inferior to any deterministic consensus here. A cryptocurrency isn't necessary and would be a distraction. But at least some limited programmability could make sense (eg for escrow).
If they deleted the blockchain db from the nodes, this is still lost.
Blockchain doesn't have anything esp. to do with data loss. It solves exactly one problem which is distributed double spending in accounting ledgers.
A blockchain solves the problem of consensus under Byzantine faults. Payments are an incidental use case, and not even a good one because managing payments including avoiding double spending can be achieved with a weaker primitive than consensus.
I suppose the idea could be that you have several different institutions holding the same data, which they know is valid because of the Blockchain.
No. Blockchain is made for managing transactions between untrusted parties. In case with a land, there is an authority managing the registry, so a standard relational DB (with optional digital signatures) is the bets option. Why someone wants to use a tool, not good for a specific purpose, for that exact purpose?
I would be less comfortable with my land registry tied to a blockchain, as soon as I lose it (who is much more likely to) it's impossible to get my land back.
What's wrong with paper records backup up a digital record and audit trail. This all seems like a solution for a non-problem to me.
A blockchain isn't stopping you from doing any of those things, if anything it's facilitating different backup models by different parties. A paper record is so much more susceptible to various kinds of risks, adversarial and otherwise. I recommend to look past the hype or hate at the technology. A blockchain is the logical extreme of where you end up when you think about how to sync backups, and you recognize that it comes with certain mathematical limitations on how much disruption you can handle.
> A blockchain is the logical extreme of where you end up when you think about how to sync backups
It's not. Blockchains are only eventually consistent among nodes. They're designed for synced backups among adversarial peers.
There's no reason for a government agency to use one internally. There are better ways to sync backups when the people with access to make updates are also authorized to do so.
Internally, you don't need it, agreed. But that is centralization risk exemplified in this incident. Which isn't necessary. Every notary could be a node. It would be a lot more resilient, and it would look a lot like a blockchain (not necessarily with a crypto currency though) if you do it properly.
You can have decentralization without blockchain. A defining feature of blockchain is that each node depends on the precise ordering of prior nodes which is a huge liability if you have network disruptions, etc, in a bureaucracy.
A git repo with cryptographically signed commits solves all the same problems without the headache.
Agreed that you don't need total ordering and hence consensus for pure asset transfers. But if you want to make any changes at all, like updating the list of nodes, you do. So in practice, you do need it. Every other proposal will fall short in a critical and avoidable way. Amending your git proposal with the necessary parts will turn it into a blockchain.
Disagree. We're talking real estate here. The time between transactions is months to years, not seconds to minutes. A git history will work fine. If there are racing transactions against the same piece of real estate, that's probably fraud, not something that should be automatically resolved.
git as-is is completely unfit for purpose and a huge security risk for this use case, because it uses MD5, which is no longer collision-resistant.
If your proposal is 'something like git, with a few modifications to make it suitable for this use case', then that's exactly what I'm proposing. What you will need, once you've considered all requirements to the best extent feasible, will be a blockchain. Eg you do need the ability to make protocol updates, no matter the time scale of transactions.
> git as-is is completely unfit for purpose and a huge security risk for this use case, because it uses MD5, which is no longer collision-resistant.
Firstly, git does not use MD5. It uses SHA1.
Secondly, since 2017 git has shipped with an implementation of SHA1 (sha1dc) that detects the collision attack you describe, which for this use case renders it a non-issue.
Thirdly, git supports `git init --object-format=sha256` which removes the whole issue for anyone who cares to do so.
I think git as-is solves the problem nicely. The only additional value blockchain provides is the ability for someone to point at it and say "look! A use for blockchain exists!" which isn't worth the downsides it'll bring.
You can't do any real money/real estate transactions without canonical order (chain of events). that's why git analogy is not applicable here. You'd need "main" branch to be canonically finalized for each and every participant.
What? Sure you can. All you need is confidence in the current owner. You don't need the whole history. Can you imagine the poor store clerk trying to say "sorry sir I can't accept that $20 bill unless you can name every prior owner in order".
Not sure if you're being deliberately obtuse here but this isn't an issue with the cadence of real estate transactions. Real estate ledgers do not need to support HFT.
If every notary is a node, you need some mechanism to ensure they perform only legitimate transactions and constantly monitor them. It is easier to just have a central authority.
You need that anyway. It's not technology that's stopping notaries from falsifying transactions in the current system.