• Ghostalmedia@lemmy.world
    link
    fedilink
    English
    arrow-up
    143
    ·
    6 hours ago

    the cloud provider’s API allows for destructive action without confirmation, it stores backups on the same volume as the source data, and “wiping a volume deletes all backups.” Crane also points out that CLI tokens have blanket permissions across environments.

    Well, there’s your problem.

    • MountingSuspicion@reddthat.com
      link
      fedilink
      English
      arrow-up
      63
      ·
      6 hours ago

      I don’t want to sound like a know it all here because I recently was reminded by a nice Lemmy person to actually TEST my backups, but damn. Every part of that is so dumb. I also have backups stored by a different company in addition to locally storing really important info. If your stuff is hosted and backed up by the same people, what happens if your account is randomly suspended or hacked or some other issue (like ai)?

      • Ghostalmedia@lemmy.world
        link
        fedilink
        English
        arrow-up
        40
        ·
        edit-2
        4 hours ago

        If your company can be taken down by Camden the college intern, it can be taken down by Claude.

        • logi@piefed.world
          link
          fedilink
          English
          arrow-up
          19
          ·
          5 hours ago

          People somehow think that they should give more permissions to Claude than to Camden. (Is that a name? To me that’s a borough and an eponymous beer.)

          E: oh yeah, and the market.

          • frongt@lemmy.zip
            link
            fedilink
            English
            arrow-up
            6
            ·
            4 hours ago

            Of course it’s a name. Camden borough/town/market is named after William Camden, 1551-1623. Using surnames as given names is a relatively common Americanism.

      • homes@piefed.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        5 hours ago

        If your stuff is hosted and backed up by the same people, what happens if your account is randomly suspended or hacked or some other issue (like ai)?

        This should be one of the first questions you get asked when you’re being interviewed for the position 2 to 3 levels beneath the position of ultimate responsibility. And if you don’t immediately have an answer, the interview is over.

        Fucking idiots had it coming

        • logi@piefed.world
          link
          fedilink
          English
          arrow-up
          11
          ·
          5 hours ago

          It’s an easy question to answer but a more difficult question to remember to ask. But I guess that’s what those 2 to 3 levels are for 😏

          • homes@piefed.world
            link
            fedilink
            English
            arrow-up
            8
            ·
            5 hours ago

            Ooo, good point. Management can be shit a lot of the time.

            But with all of those layoffs because of AI, those 2 to 3 levels get collapsed into one, and we’re left with the trainees running the show.

            And here we are ¯\_(ツ)_/¯

        • MountingSuspicion@reddthat.com
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 hours ago

          Not to give myself more credit than I deserve, but I did test them upon setup, and had restored from backup 2 years ago. I didn’t have any ongoing checks other than to ensure a backup happened. I have since instituted yearly checks of the backups themselves, but I did feel dumb when I realized how vulnerable my data was.

          • stoy@lemmy.zip
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 hour ago

            Hehe, I ment no disrespect towards you, I just find that to be an excellent expression to explain the importance of testing backups to non tech people.

          • frongt@lemmy.zip
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 hours ago

            So in the event of a failure, you’d be okay with reverting to that last known good backup from a year ago?