Or maybe I've been watching too much Battlestar Galactica
So yes, we have WAY too much shit on the Internet that has zero reason to be there - and we have way to many connections and content flowing between orgs without any kind of assessment as to what the content is, it's authenticity, etc.
The vast majority of ransomware incidents happen via spearfishing over email - pretty nuts that literally one erroneous click by a user can take down an entire network.
Think about that. Talk about inherent fragility!
And its hella hard to hack paper in a locked filing cabinet, in a locked building, filled with police.
In person documents:
requires being at a single location in the world
single copy
in secured storage
in a secured building
filled with people who can shoot you legally
Online documents: Can be done from anywhere in the world
infinite copies can be made easily
1 hack can un-secure the data
threatening to shoot a computer doesn't have the same impact
Its really a computer hacker versus traditional spycraft. Spycraft isn't impossible, but does require assistance and tech from nation-states, and is prone to a set of really bad negative eventualities if caught.Other documents, will need a whole process of retrieving information, copying it, adding info, sending it, checking it, sharing it with other people. Police officers' own personnel records might be an example. If you only store these on paper, informal access procedures might be developed. For example, the civilian secretary is used to certain people requesting copies of 6 or 7 files at a time, so they don't always keep track of what was asked for. Unofficial copies get made and kept in someone's desk drawer so they don't have to spend a morning going over to the main HQ. And so on.
Now you have the worst of both worlds - lax security, but also no hope of the traceability and fine-grained access control of an electronic system.
A threat actor intent on extracting the informant list of the DC police will have a completely different approach to the hack, probably involving advanced surveillance, infiltration, bribery, etc.
It's also why SMS text messages do not meet the criteria for 2 factor authentication - it's trivial to social engineer phone companies into moving a phone number to a new phone - presumably one you would not have. Authentication apps are a PITA to move to new devices because having a way to move your keys around without some reliance on meatspace defeats the whole goal of "something you have".
Obligatory "if you're in the US, then yes - elsewhere, it depends". In the UK, obtaining a PAC code is a bit more complicated/non-trivial for the attacker. I'd consider it fairly safe to use SMS 2FA over here.
[1] https://www.thetrace.org/2016/08/atf-non-searchable-database...
Think how insane it was for the OPM to keep clearance files in one big networked database.