Conversation
Notices
-
Embed this notice
feld (feld@friedcheese.us)'s status on Thursday, 17-Oct-2024 23:11:09 JST feld
me just trying to delete an extra account i opened, so i send them an email as required:
> Thank you for your request. This has been escalated to our GDPR team. We will update you in two to four weeks. I hope this is satisfactory.
guys just press the delete button we don't need to involve another team. i know you get like one delete request per month at this site because it's a site literally nobody uses unless they're network engineers, so just do it.-
Embed this notice
James 🌈💜 (shaknais@mastodon.social)'s status on Thursday, 17-Oct-2024 23:15:15 JST James 🌈💜
GDPR also requires deletion from offline backups, and all logs, and getting someone to do that when no one actually gets given the time to field those requests, is where the difficulty comes from.
-
Embed this notice
feld (feld@friedcheese.us)'s status on Thursday, 17-Oct-2024 23:15:15 JST feld
@shaknais so GDPR made it illegal to have append-only backup strategies now, eh? -
Embed this notice
feld (feld@friedcheese.us)'s status on Thursday, 17-Oct-2024 23:23:23 JST feld
@shaknais why does Europe hate tape archivers so much -
Embed this notice
James 🌈💜 (shaknais@mastodon.social)'s status on Thursday, 17-Oct-2024 23:23:24 JST James 🌈💜
Yuuuuuup.
You're maybe allowed to purge-on-restore, but that's annoying and frustrating, too. And could be challenged legally, because you might be holding identifiying data to notice what to purge.
-
Embed this notice
feld (feld@friedcheese.us)'s status on Thursday, 17-Oct-2024 23:52:16 JST feld
@shaknais really though how do you deal with this in practice?
tape backups cannot be used now because you can't selectively remove data
restic / borg? No, those are gonna be a problem too because, again, you can't go back and delete little pieces of old backups
ZFS snapshots? nope. can't edit them.
What are their options now? Regular disk and object storage? The backups have to be writable now
This is exactly what the ransomware people want. It makes their attacks so much easier if all your backups must be writable by law. There won't be an option to just tell them to piss off and restore from your super secure backups because they legally cannot exist
-
Embed this notice