And of course everything didn't work perfectly, it did however work "perfectly fine", which means "very well" or "good enough". Meanwhile, adding in network connectivity to anything vital these days is just insanely dumb.
No software is secure, and will never ever be secure. Ever. Anyone who thinks that software can be made secure, is 100% wrong, period. My point is that the advantages aren't worth the disadvantages.
And as a third option we can have efficient digital systems that aren't plugged into the Internet. (Presumably the Internet could have a copy that's regularly updated.)
I've seen 'competent' backup solutions which had backup rotations that expired older content. And I've read post-incident responses where hackers slowly corrupted older records. And (via reading corporate wikis and docs), determined how long they had to wait, for backups to become tainted.
But I agree. True competent backup methods, including periodic backup restoration tests and other methods, can ensure a degree of protection. Still, one can end up with months of "bad backups" due to a hacker interceding in the process or corrupting records slowly, thus invalidating more recent backup sets post-hack. While this didn't happen with Equifax, the hackers were in there for 8 months slowly exfiling information.
So you can have a load of backups with questionable integrity.
Really, what I'm comparing here is indelible backups vs not. It could be holographic, write only storage for all I care. It's just that "paper" backups, which move to microfiche, have a century long history of how to deal with it. How to ensure they're good. How to keep duplicates, resolve security, and all that.
Meanwhile, most people dealing with the software side simple think "Oh, we can make this situation secure. We can make software secure."
This thought process is entirely wrong. Software is never secure. If you use software + a database or other store for data, it's not secure. And so, placing it online is just plain stupid.
Of course, you speak to other options. No external network connection, for example. And this is all well and good! And it significantly reduces the attack vector.
But of course, and lots of high security environments do this, you then have to ban staff from bringing in all phones, computers, and other devices. I read a post-action report where people's phones were hacked, and basically acted as a 2G modem (at the time) into wifi on an isolated network of a nuclear power plant. And due to the thought process of "We're 100% air gapped, who cares!", the hack was apparently an easy one.
But really, the difference is... how many people can attack your citadel.
The internet means billions. No network connection means hundreds.
It's just that simple. And I think you agree, mostly.
Suddenly your entire argument shifted in my head and I fully agree.
Might be something there I can learn about myself then :D
A sophisticated genius hacker in a different country can’t touch your paper records, but an absolute moron with a bic lighter can destroy records just as effectively. Hell, an irresponsible clerk can do an incredible amount of damage just by misfiling things.
Duplication literally doubles costs in the physical world, and has the downside of being very hard to keep in sync. A bank keeping paper ledgers would be absolutely fucked if they had to switch to a backup ledger that was more than a few hours old.
On net, I believe that digitalized documents are a net improvement.
Put some desktop-size tape robots in several government building closets, and task someone with switching tapes weekly, and you can achieve more reliability than multiple huge paper archives.
The real danger is that we ’ll be so careless we’ll discard other enduring ways of doing things before we smarten up to their particular benefits.
My hope is that disciplined people still have an intuition for this, even among the digitally steeped. Sysadmin/ops types tend to a culture of diversifying backup location and even media type. Maybe that can reach back to human legible hard copy.
If we start thinking along the lines of technology has risk and we shouldn't use it, we should go back all the way to the discovery of fire as we all know fire can cause a lot of damage if in the wrong hands.
In as software is not secure, and can not be made secure, using it for important records storage makes zero sense, unless you a) have full backups offline in physical, non-digital, read only medium or b) just don't do it online, at all.
And my point is, it's not worth the convenience.
Think about it. To destroy the public archives, of which there is typically more than one, you must travel to said location, breach it with weapons and other means, and destroy it. Or, you can sit in your parent's basement in your pajama's, and hack and destroy.
There is not even remotely the same risk profile.
And if you think something is "good" because 'the world thinks it is good', then I have to ask you why you're validating something via popularity. You know what else was popular? Fossil fuels. Smoking. Using uranium in makeup for women. Something being accepted, and being fun or convenient, doesn't make it correct, sensible, or right.
So please describe the horrible and incredible "gigantic convenience". Because I lived before the internet, and now after, and yes it is convenient.
But it certainly isn't a 'gigantic' one, nor is it sensible compared to the insane attack surface and risk.