‹ BackHN Continuity

Thread

AWS says it can't restore some data from mideast facilities struck by Iran

530 points · 452 comments · berkeleyjunk

  1. curuinor · · focus · HN ↗
    They guaranteed 11 9's durability, didn't they?

    e: Yep

    <a href="https:&#x2F;&#x2F;aws.amazon.com&#x2F;s3&#x2F;storage-classes&#x2F;" rel="nofollow">https:&#x2F;&#x2F;aws.amazon.com&#x2F;s3&#x2F;storage-classes&#x2F;

    1. [deleted] · · focus · HN ↗

      [deleted]

    2. jonahx · · focus · HN ↗
      I don&#x27;t think this has any teeth. They don&#x27;t compensate in the event of loss afaict.
    3. rbanffy · · focus · HN ↗
      Considering all the data they have globally, they might still be compliant.
    4. stackskipton · · focus · HN ↗
      Even if they have payable SLA on this, most SLAs have Acts of God and Acts of War exemption.
      1. lbreakjai · · focus · HN ↗
        But do they have Act of Special Operation exemptions?
        1. eastbound · · focus · HN ↗
          I&#x27;m going to reword my Terms of Service this second to add &quot;any military operation&quot; next to &quot;acts of war&quot;. But I&#x27;m sure we&#x27;ll then have to demonstrate whether paramilitary are assimilated to the military.
          1. MisterMunchkin · · focus · HN ↗
            I was just reading an insurance policy and it said &quot;any war, including undeclared wars&quot;

            The insurers always know how to weasel out of it.

      2. Y-bar · · focus · HN ↗
        &gt; US refuses payout for soldiers who died in Iran &#x27;because it isn&#x27;t a war&#x27;

        &gt; In response to another question, Mr Vance rejected using the word “war” to characterise US operations in Iran, saying there was “no active shooting”.

        <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49596955">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49596955

    5. advisedwang · · focus · HN ↗
      They say it&#x27;s &quot;designed for&quot; 11 9s, not guaranteed.
      1. the8472 · · focus · HN ↗
        But if they want to design for extreme probabilities you need to account for tail risks, so their design should have included a missile defense system. At some point you need to start worrying about asteroid defense too.
        1. JCharante · · focus · HN ↗
          Ah so that&#x27;s why we need a lunar base. To uphold S3&#x27;s 11 9s of availability
    6. beejiu · · focus · HN ↗
      The SLA excludes force majeure.
      1. LastTrain · · focus · HN ↗
        This
      2. the8472 · · focus · HN ↗
        Making a probabilistic claim while excluding a factor that dominates those statistics is... is quite creative accounting.
        1. mpyne · · focus · HN ↗
          Are you saying that most data loss happens because your data center gets blown up in a shooting war? Like, AWS is the first digital service provider to lose data in decades?
          1. the8472 · · focus · HN ↗
            I&#x27;m saying that if you have eliminated more mundane failures like dying harddrives, cosmic rays and so on from your systems and your calculation ends up with 11 nines then actually those &quot;force majeure&quot; events are probable enough that they dominate whatever other residuals are supposedly hiding in those last 0.0000000001%.

            The region has seen a bunch of wars in the last 100 years, so the annual war-rate is &gt; 1%. Even if we generously add the assumption that only 1 in 100 wars affects a datacenter you can see that wars become a major source of correlated hardware failures that they need to solve to actually deliver that kind of reliability.

            1. mpyne · · focus · HN ↗
              Cosmic rays and dying hard drives are not force majeure though.
            2. ployable7 · · focus · HN ↗
              You don’t want to blend probabilities like this, because the tactics you use as a consumer vary between the two. If you consider 11 9s like “object AFR”, you might build systems that are resilient to very occasional single object loss. And it’s useful to know at what rate that might occur.

              Whereas with these force majeure events you’d want a complete DR setup, and it’s typically an async recovery. Here it is useful to understand the fault domain (single server or single building or multi-building) so you can plan.

              Blending the two numbers doesn’t help you build better against the systems. And the force majeure events are rare enough that they won’t happen … until they do. I’m not sure that knowing the precise probability that Iran would attack a gulf nation would change the fact that if they do, you need to have a DR story.

              1. the8472 · · focus · HN ↗
                Seems like begging the question to me. You can&#x27;t blend the numbers because amazon didn&#x27;t blend the numbers. If they did and miraculously still arrived at 11 9s then that would also cover things such as wars and natural catastrophes, e.g. because they do offsite backups internally.
                1. ployable7 · · focus · HN ↗
                  I’m not saying you can’t blend the numbers, I’m saying you shouldn’t blend the numbers. Because one number doesn’t communicate what you actually need to know to build.

                  You want to know how reliable the service is in steady state. For example it’s useful to know that S3 is effectively lossless in steady state whereas EBS volumes have an AFR of about 0.1%. You build your apps very differently between S3 and EBS knowing this. You can build highly resilient applications on each, but you code them differently, informed by these design goals.

                  You separately want to understand the failure modes that will require you to fully recover from backup. For example knowing that cloud storage is resilient to everything but region failure would inform you that your backups should be out of the region, not just a bucket in the same region. You don’t get that perspective from just a 9s number.

        2. mjr00 · · focus · HN ↗
          Force majeure carveouts are really common in every type of contract.

          You should check your home insurance contract, for instance... It likely would not cover an ICBM strike.

          1. sire-vc · · focus · HN ↗
            Somehow I feel like the biggest post-apocalyptic problem will be the loss of home equity due to uninsured damage causing a collapse of financial markets.
        3. eli · · focus · HN ↗
          I think it&#x27;s what most people comparing provider SLAs would expect
        4. unethical_ban · · focus · HN ↗
          Are you suggesting that their technical documents have separate availability numbers to predict geopolitical events and war?
          1. throwawaythekey · · focus · HN ↗
            The sales pitch should change from &quot;probabilistically we will NEVER lose your data&quot; to &quot;you are most likely to lose your data due to wars, terrorists, software bugs, someone losing the master encryption key, the government forcing us to...&quot;.

            Offsite backups are sadly rare these days, and aws sales is the main reason why.

        5. mitxela · · focus · HN ↗
          Creative accounting works and is good because it works. If your customers give you more money because you lied to them, but it&#x27;s legal, then it&#x27;s good.
      3. oatmeal1 · · focus · HN ↗
        Excluding war as force majeure in the Middle East is the same as excluding high tide as force majeure building a sandcastle at low tide.
        1. Y-bar · · focus · HN ↗
          This is very on point. While I am not legally trained in US law, and especially not in any Middle Eastern law, I have a enough knowledge on the law in my country here where I live…

          Invoking force majeure requires the entity to prove all three following to be true:

          A. That the event was unexpected and therefore unavoidable.

          B. That the event was outside the control of the entity.

          C. That the event made it impossible for the company to resolve the issue.

          War in the region is as you say rather common unfortunately. The fact that AWS is used by the IDF (<a href="https:&#x2F;&#x2F;www.972mag.com&#x2F;cloud-israeli-army-gaza-amazon-google-microsoft&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.972mag.com&#x2F;cloud-israeli-army-gaza-amazon-google...) should be considered a factor whether or not their data centre became a more likely target or not. What remains is the ability or not for AWS to do multi-location reduncancy.

        2. roryirvine · · focus · HN ↗
          As someone who ran a tech company in Northern Ireland at a time when violence was much more common than it is today, I can tell you that our force majeure clauses always disclaimed liability for &quot;riot, violent disorder, civil commotion, and acts of unlawful civil unrest and terrorism&quot;.

          How could it be otherwise - do you expect AWS to have its own army and missile defence system?

          1. oatmeal1 · · focus · HN ↗
            The difference between you and Amazon is hundreds of millions of dollars in political donations and lobbying. Amazon certainly has the political connections to make defense of its datacenters a national security priority of the strongest military on earth if it made it a priority.
    7. jameshart · · focus · HN ↗
      The footnote which says that is the design durability against equipment failure literally begins:

      &gt; In the unlikely case of the loss or damage to all or part of an AWS Availability Zone, data in a One Zone storage class may be lost. For example, events like fire and water damage could result in data loss

    8. [deleted] · · focus · HN ↗

      [deleted]

    9. shepherdjerred · · focus · HN ↗
      It seems unreasonable to blame Amazon here. The AZ was destroyed. Are they supposed to have missile&#x2F;drone defense?

      I&#x27;m not going to complain to DoorDash if my order is delayed due to a car crash

      1. Edman274 · · focus · HN ↗
        If a senior leader at Doordash swore to God that your sandwich would 100% guaranteed make it to you, regardless of whether or not there was a car crash, then yeah, maybe you should complain
        1. shepherdjerred · · focus · HN ↗
          Yeah I agree with you. If they made a specific promise to some unlikely case out of their control, then I would expect compensation.

          Did Amazon make such a promise? They didn&#x27;t as far as I know. My understanding is they provide specific guarantees like given an AZ outage, your data is still safe (provided you architect correctly).

        2. earth-tattoo · · focus · HN ↗
          Correct analogy would be: they promised to make 3 copies of my sandwich, from 3 different restaurants, and deliver them by 3 different cars, taking different routes, in case one of them gets in a crash. But in this case all 3 restaurants were bombed by Iran!
      2. jLaForest · · focus · HN ↗
        Wild berries has missle defence now, why not Amazon?
    10. kmeisthax · · focus · HN ↗
      Hot take: if you have a service that is 11 nines reliable, but there is an underlying component whose reliability is lower, cap the nines to that component.
    11. ciberado · · focus · HN ↗
      If they haven&#x27;t changed it recently, 11 nines is the durability target by design, but it is not set in any SLA. the S3 SLA is focused on availability.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.