Nine PBS sues Iron Mountain over blocked access to archival data
current.org
current.org
Just email…
Edit per “no contact on profile” comment:
Contact info@rsync.net for more information, and answers to your questions.Which, in practical terms, means "while I or my investors have money". These guys have 70 years worth of data, can you guarantee to keep it for another 70? The real answer to these kinds of problems is managing the data yourself
Taking its name (Lots of Copies Keeps Stuff Safe) from the idea that a file is more likely to survive if it has multiple copies stored in multiple places, LOCKSS software allows libraries to create preserved digital collections out of materials that would otherwise be accessible only through a licensed academic subscription. LOCKSS has agreements with academic publishers to permit libraries to store local copies of content that is usually only accessible through web-based subscriptions, enabling post-cancellation content access.
https://coptr.digipres.org/index.php/LOCKSS_(Lots_of_Copies_...
Libraries were the archives for newspapers and local public information.
That's making a lot of assumptions. I host some of my backups on what is effectively a reseller of S3; was that decision corrupt?
But, yes, PBS does bear some responsibility here. If you leave your car in a parking lot overnight with the door open and the key in the ignition, the thief is still wrong for taking it, but there's a limit to how much indignity you can have.
PBS is an association of local public broadcasters, most of whom are SEVERELY underfunded.
As the parent entity, the national PBS has a responsibility to guide and even mandate policies and provide best practice guidelines or even offer support and assistance in burden sharing arrangements.
PBS has long now had major structural challenges due to things like internal corruption and overbearing control by the well funded chapters without commensurate responsibility.
As with many such decentralized membership organizational structures, incentives can often be very misaligned between verticals and laterals.
Don't blame corruption for what was most likely extremely strained budgets. Local public access TV stations like KETC (Nine PBS) tend to be severely understaffed and underpaid.
Realistically, they went with OSS because the quote for a local MSP was cheaper than the cost of hiring additional headcount (a $70k salary ends up costing roughly $100k for an employer).
(Source: occasionally dealt with these kinds of accounts back when I was an SE and later PM)
Edit: I'm right - they only have 1 IT/Software employee managing the entire organization which only has a budget of $30M after losing $1.8M in federal funding.
Oof, that is a horrible position to be in with so many dicks on HN. You'd assume SWEs would have sympathy for other SWEs.
Some HNers should have been taught better manners by their parents or should have at least internalized the lessons from Arthur as a kid [0].
If that employee sees this post - I want to say THANK YOU. It's a hard job.
Only if you haven't been reading HN very long!
I hate HN and how it has gotten worse and worse as the years go by. There are a couple basic changes that the mod team could do to help alleviate the degradation but they aren't doing it.
You're going to have to unpack the assumption here: are you alleging that there was a kickback in the procurement process?
Consider this: the utility that provides the electricity and the ISP providing internet also do not have a direct relationship with Nine PBS, but will be essential in carrying out the court order. Does the judge have to expressly name every transitive party responsible for carrying out the order? Time will tell, but to me the answer seems "no."
In fact, I'd expect you to need a seizure-warrant/distinctly-named-but-to-the-layperson-identical-court-order for my place as, among other things, I don't think I am in a position to legally have standing to challenge an order that's not mentioning me, and lack of me being an active flight risk would probably preclude you from arguing exigent circumstances to secure the dev kit without a judge ordering me to let you.
TL;DR: "complying" with a court order that's filed against a 3rd party is, IMO/AFAIK, a voluntary act, specifically because the party not mentioned in the court order AFAIK has no legal standing to challenge that very order of in court. _Precisely_ because they're not legally mandated to comply, at least not beyond perhaps taking a precautionary legal hold on the referenced information to not get accused of aiding in destruction of data in case the court-ordered party directs the non-mentioned party to delete through the regular customer relationship channels (API? Whatever else?).
Iron Mountain just doesn’t want to be in the middle, and I can see why. OSS went defunct, PBS files a lawsuit, guy buys OSS so PBS pauses, guy now claims he was defrauded into buying it, and somewhere in the middle nobody from OSS showed up in court so there’s a default judgement to turn those over.
I would probably also refuse to turn over the documents without a court order. The whole situation is a mess and the only way to be absolutely sure you aren’t going to get dragged into it is a court order for specific performance.
PBS probably isn’t going to sue them for releasing the docs, but who knows what OSS will do. It doesn’t sound like anyone even really knows who owns OSS at the moment.
I'm sure Iron Mountain will be happy to turn over the data, but to cover their ass in terms of their agreement with OSS, they need the cover of a court order otherwise they would likely be in breach of their contract with OSS
Storytime, since I'm no longer under NDAs for the company, over a decade ago somewhere that I worked, a disgruntled employee who decided to quit, made a point to within a week of quitting, take a whole bunch of important physical documents they had (because, FBOW, our email and other data retention was so bad, it was safer to have them as prints) and threw them all in our fancy Iron Mountain 'disposal' bin.
Apparently due to the agreement with them, short of a court order, only specific employees/titles in the company were allowed to be the persons to retrieve them.
Keeping that situation in mind, it's clear that this dance for better or worse is part of their posturing as a retention center with very strict rules to ensure compliance while also avoiding snooping.
I've dealt with them as well - they don't like being in this kind of position either.
[0] - https://ironmountain.jobs/manassas-va/armed-officer-safety-s...
[1] - https://ironmountain.jobs/boyers-pa/security-officer-armed/6...
They weren't talking about breaking into the Iron Mountain facility
That said, I would be willing to bet that doing such an act, even as a client, would be problematic on other levels.
Let's remember; part of this whole contract with a company like this, is they are guaranteeing that your organization is following document retention processes. The sort of stuff that makes it really easy to pass things like a SOX audit.
Cause, I've worked at other places. The kinds of places where you come in on a Saturday, there's a whole bunch of document bins out in the middle of the office that weren't there on a Saturday, everything is gone by Monday, and a bunch of people one to two slots under the C level resign within a week, and within the next 6-12 months all of the office gossip is either the bankruptcy proceedings impacting operations or the civil RICO lawsuit from the departed founder.
Anything else is the sort of stuff that causes blog posts and news articles about data breaches to be written.
It’s exactly like the above but it’s presented as if the data sits neatly on two drives stored in a safe and all you have to do is mount them to see the unencrypted data.
If you don't want on site, a second off site provider, 50TB on backblaze would be an extra ~$350 per month (prob less if they were to commit to capacity instead of using their PAYG service)
I wasn't 100% sure, but the data backs this up[0]; the "3-2-1 backup rule" is a relatively modern concept, at least by that name. I also remember things like "have one backup in one place, another in another place" since before this mnemonic, but I feel like it's unfair to judge a 70+ years archive on something that just recently actually became a widespread mantra.
- [0] Interestingly, Ngram (https://books.google.com/ngrams/graph?content=%5B3-2-1+backu...) says ~2010 while Trends (https://trends.google.com/explore?q=3-2-1%2520backup%2520rul...) says slow build up from ~2020, guess "everyday" language would sit somewhere around those two different truths.
While statistically it might equate to "unlikely" as you state, the fact it did happen, I now have that experience that is not forgotten. Never bring a large storage pool into PROD immediately after the array finishes striping. Put it under load for a period of time first. The question remains on how long that period is though which is probably answered with "how paranoid are you"
While there's always luck involved, dying during warmup and not two weeks later is the expected experience for drives that defective.
So what happened to you wasn't that you made a backup and then it failed so fast you couldn't use it. It's relevant to what I was saying is unlikely, but it's not an example of it.
Plus at zero weeks or even two weeks you have the previous backup system around. If you have a big simultaneous failure 6 months out, that's a scary situation, but that's much rarer.
I mean, that 70+ year old archive must have been digitised at some point, unless Iron Mountain was storing the reel to reel tapes and/or film from the original recordings. So some "modernation" has been applied to it since its creation.
Now add in tons of other legacy formats and digitising becomes a pretty big cost for a public station.
They signed up with them in 2019. Not long ago.
Even if it is a "new" concept, common sense isn't. Pretty much anyone who cares about their data will do the due diligence, and this is not something that requires technical chops. This has been a concern for well over 20 years!
It really sounds like some senior management trying to be cheap.
They probably have 1-2 IT staff, who have been paid significantly under market value compared to private sector.
Management was not management of an IT organization, and probably did not really understand the trade-offs or what they'd lose by not spending more money on IT. Their IT staff was probably super busy and over-worked and also (not to throw them under the bus) not experienced enough to really advise them, and if they had and had tried to advise them, would management have decided that doing less programmatic work to pay for it, and having IT people at least temporarily spend less time on whatever they do to support regular business, to set up and support backups, was worth it? Maybe, maybe not. Again, the managers probably have little experience with IT. The whole organization is probably well under 100 people.
Source: I work in non-profits.
Why is HN always focused on suggesting there's a person who could have easily made the right choice if they weren't an idiot?
I'm familiar with the dynamics of such places.
If they actually go through a proper lawsuit, my guess is the lawyers will cost more than whatever they'd have to pay for redundant backups by an order of magnitude. Which means they probably won't go to court.
I don't know why they didn't decide to do that, I guess they just make poor decisions to be cheap. Otherwise it's a complete mystery.
Also, this TV station has not been sending their show archives to Iron Mountain for the past 70 years. Probably what happened was: In 2019, they had an on-site or nearby archive. Then some enterprising IT director came along and convinced management that they would save a bunch of money and time by outsourcing everything to a third party who said they could do it for cheap. Very confident in their genius, they then scrapped their own archive entirely.
Part of me pities them for ending up in this situation, the other part of me believes they got everything they asked for.
Which is not as thorough, but still makes the point that you should do more than one backup
Probably! The important part is that your pretend story time supports your base desire to blame the victim!
I've heard variations of this all the way back to some 1990s vocational IT courses in the country I live, and it wasn't even technologically advanced at the time. It's hard to have any sympathy for someone who misses this concept in today's age.
Non-profit IT has always seemed, to me at least, to be a land of compromises. There's rarely enough money, knowledge, or time to do things "the right way", so you have to do the best you can. If I could only choose one backup to have, it'd be remote on a provider like Iron Mountain. It would seem as if they are storing things on Iron Mountain through an intermediary company, who may or may not have actually paid the bill.
So, y'know, fraud's a possibility here.
In a free society, we don't need state-run media.
The US is not a "free society".
Which is why the BBC, ABC, CBC, etc exist in civilized societies.
I think this is a kind of time-sequence fallacy which I've seen before on HN. It's not that "we don't," but that, perhaps, "we wouldn't."
E.g., I study the pieces still standing in famous checkmate positions and decide to start the game using only those pieces. Bad strategy.
At 50TB, they probably could have Just™ written three copies of the data to a pile of disks, sent one copy off to Iron Mountain, and kept the other two copies unplugged in a safe. I can understand the DIY solution might not be allowed for insurance reasons, but it's something so cheap they probably could have done both. Unless OSS was just taking them for a ride on storage, which... well, actually that seems pretty likely.
[0] To put it simply, there is no good medium for the archival of digital information. HDDs are not shelf-stable. Flash is even less shelf-stable than disk. Sony is actively trying to kill optical. LTO is shelf-stable, but good luck buying known-good or new drives for old formats. The only option is periodic cloning and verification of offline disks, or keeping all your disks online, which is the NAS solution.
IM seem to be holding KETC's data hostage, which is Not Cool.
Maybe they mixed data from many companies on the same volume like S3 does. Maybe there were ACLs on that. Maybe it includes PII. Maybe it's a bunch of shards and needs an index on OSS servers to reassemble. Maybe it's encrypted by keys OSS had.
2. That doesn't actually seem to be Iron Mountain's argument here, though the reporting isn't crystal on the point.
There is no way for Iron Mountain to determine who OSS’s customers are, and their permissions, without help from OSS itself.
And because OSS is defunct, they can’t get that help.
How does AWS then determine which files are whose when my angry clients go knocking on their doors because I've decided to disappear?
2 it doesn't say either way. From owning systems like this, I'd assume there's some degree of "we have no idea what's in this bucket and can't just hand it over to random person asking for it".
Context: I owned a photo backup startup. 8.6 billion photos. Some might be yours, most are not. If you went to AWS and asked for a copy of the bucket, they rightfully wouldn't have complied.
Sounds like they paid a company to digitise all their old tapes, and store the results. They possibly still have all the tapes (on site) and are just trying to avoid paying the costs to redigitise them.
But, it’s also quite likely they destroyed all original the tapes after digitisation, and this was the only copy.
https://www.ibm.com/history/magnetic-tape
Usually what kills the tape is the little reflective stickers on the back side of the tape material will fall off and render the tape useless since the machinery can't tell where the recording starts. Apparently I bought cheap mag tapes back then.
Full headline: PBS broadcaster loses access to 50TB of data comprising 70 years of TV history after contracted cloud storage vendor goes defunct — public TV channel sues Iron Mountain data center, which hosts archival materials, to ensure preservation
The channel’s attorney also reached out to Iron Mountain to inform the company of the pending case in Colorado; Iron Mountain finally admitted to holding the data. Iron Mountain initially agreed to turn over Nine PBS’ data, but it eventually backtracked and claimed that OSS owned the data it stored. Because of this, Nine PBS now has no choice but to sue Iron Mountain, too, to ensure the data is not deleted.
This does make sense. I'm guessing the first request some rep just went sure its you're data why not, but in reality, it's OSS's data, and you paid OSS to store it. It's also likely encrypted in someway.
TLDR still, is especially when it's a reasonable amount of data, just have more than 1 backup.
Likewise if I store data with a cloud provider. Sure, Iron Mountain shouldn't just offer it up without proof, but if I give them notice of a legal case they should be sure to hold on to it, and if I win the case they need to hand it over to me. All I need to do is provide proof that I am the rightful owner of those goods.
Also your storage company case is actually it's own can of worms, see the Lego drama from a couple months ago about that. It seems obvious, but in the eyes of the law there's more paperwork than you'd think.
That is to say - I really doubt anything about this is remotely simple or straightforward, but I'm sure it's all lucrative for the lawyers involved.
You are a subtenant. The tenant went bust. The case law on this is settled. Depending on state, you either have a period of time to vacate the premises or you can/do become a tenant of the property owner. People have been subleasing rooms/apartments for hundreds of years, so every possible scenario you could imagine in this space has been litigated to death.
That is real estate.
American case law about data stored on computers is that whosoever owns that computer owns all the data on that computer. Which is why US privacy law is far weaker than EU privacy law (where you own the data about yourself). I think pets.com was one of the very few exceptions where the TOS said "we won't sell your data" and the bankruptcy liquidator said "it is an asset, we sure will sell it" and the courts said "no you can't sell it".
I thought this would be like the backups I've heard broadcasters have of every broadcast they've ever had (I've heard of people being able to request 20 year old news clips before).
But just 50TB of data? Duplicating that would have been cheap and trivial.
I'm an independent photographer and I have my 20TB drives behind my monitor, backing up to backblaze with an offsite synology. Keeping this archive up does take time and money, but PBS should have the budget and IT deparment for this.
It depends - especially if you go back further than 20 years. The Wikipedia article for "Lost television broadcast" goes into detail:
Data requirements for this would be far, far lower than what is considered standard now.
Seriously. I'm just a random nerd and I have a home server with 96TB of raw disk space divided in to two RAIDZ1 pools which cost me around $2500 to build five years ago and has required basically zero maintenance since then.
Hard drive prices are absolutely bonkers right now but even with that in mind if I were to build a modern version of this same machine I could do it for under $10k using brand new hardware and it'd have double the storage
I wonder how they got the contract? Seems to be 4 people 'employed' at this company. Of which, one is retired, one is "Linkedin Member", one is a controller and the last one is a social media person: https://www.linkedin.com/in/isabelle-anderson-7aa250b5/
So, just the person to deposit checks and a social media person to get paid. Who exactly is left to work on storage infrastructure?
a) OSS is a colocation customer with its own hardware colocating it inside an Iron Mountain datacenter. In which OSS owned the bare metal and paid iron mountain for rack space and power.
or
b) OSS is a dedicated hardware customer of Iron Mountain running a service on bare metal owned by Iron Mountain, and has gone defunct, leaving behind a bunch of servers/storage arrays that would in normal circumstances get wiped/reprovisioned.
From the point of view of a customer of OSS (PBS), that's two extremely different things.
If it's scenario A, I don't see how PBS has any claim against Iron Mountain. Your typical datacenter colo host for bare metal hardware owned by a customer has no involvement whatsoever in the condition or operation of the data, operating system, filesystems, RAID arrays, ZFS, etc of how the customer has set up their environment. Nor any ability to do anything with it. A colocation host that hasn't been paid for its rack space and power will typically have clauses in its colo contracts allowing for seizure and sale of abandoned hardware after a certain period of time.
Nine PBS might well have non-digital data, but it's clearly not the data this article is about.
That $4k plus the free shoebox could have saved them quite a bit in lawyer fees :P
Still, it is 70 years of video from that PBS station.
With the stuff about "corruption" and losing the data if the server is shut down, I wonder if part of the concern is about losing in-memory decryption keys.
That's an entirely reasonable concern and explains why Iron Mountain wants OSS on the hook for fulfilling this order rather than trying to yolo it themselves.
(huge fan of Stokes as a fellow archivist, recommend the documentary on her: https://en.wikipedia.org/wiki/Recorder:_The_Marion_Stokes_Pr...)
Someone dumping their Twitch stream or random Youtube content into the storage system will certainly have that content deleted and be banned if prior arrangements have not been made, for example. Don’t do that.
https://old.reddit.com/r/DataHoarder/comments/sq6wbq/please_...
Agreed, no doubt about it.
> There has been instances where they delete files without warning with the only explanation being that they don't meet TOS
What sort of content? All the content I've judged to be of public interest and uploaded to Internet Archive, is still online there today. But I'd understand that depending on the type of content, that might not be true for everythibng.
As far as I remember the issue may have been that archive.org already had a copy of what had been uploaded, but they deleted it without warning and then refused to offer an explanation
So it may have been a legitimate deletion, but poorly executed
https://www.newson6.com/story/5e3687772f69d76f6209d656/tape-...
Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway.
— Andrew S. Tanenbaum
Cram a few 12 TB drives into that sucker and you’ve got all the storage you need for their whole 50 TB archive.
The drives are spendy, but $/TB on media is lower than anything else. 30-50TB tapes are still pretty expensive, but so is all storage these days (I hadn't really looked in a while, yikes)
For some reason they also have an LTO-5 drive for $1200 and tapes for $20/TB. Which looks a lot better today in a comparison with hard drives than it did a year ago.
If you had an account with them, how would you feel if some unknown third party could call them up and go "Uh hello you have my data give me access plz trust me bro"
Okay hang on now.. that strategy comes with its own risks. Risks that I imagine PBS was trying to avoid by using a third party that specializes in archival data storage. This is a silly takeaway.
Edit: I was too quick to comment. I think they are suggesting that the NAS should have been used in addition to the third party storage, which is actually a great takeaway.
I think they just put that stuff in so they could shill their affiliate marketing articles rather than out of any actual concern.
The 3-2-1 includes the production data itself.
You have one copy of data (the data that needs to be backed up), and you have two additional copies of that data (the "3" in the strategy), where one of the backup copies is stored offsite (the "1" part), which naturally follows that it satisfies the middle "2" also.
For over a decade we used 4-3-2 strategy, but it got expensive fast and due to ever evolving budget cuts, our (local gov) customers weren't ready to pay the extra.
There's also 3-2-1-1-0, but that's just a fancy way of saying you _really_ should be doing those restore tests you never seem to have the time, because ransomware can and _will_ corrupt your backup copies.
edit: the absolute minimal setup that still satisfies the 3-2-1 rule: 1) you have your data in production directory on local NVMe stick inside your computer, 2) you copy the original production data to another directory inside the very same NVMe, 3) you occasionally manually copy the production directory data to USB and store that USB inside the shed in your backyard. - That's it. Now your home data is covered by the coveted "3-2-1" enterprise ready backup strategy.
10 years ago, this was a lot of data. It isn't anymore and it makes it that much more bizarre that they're having that much trouble getting it back. It would be less to just give them access and let them download it themselves and perhaps stick it somewhere else temporarily than to pay lawyers to deal with legal filings.
To put it in vaguely physical terms, what once was a university library is now a good solid bookshelf full of stuff. Legally wrangling over a huge library is one thing, but if it's just a bookshelf, metaphorically, let them come in for an hour and clean it out themselves rather than bringing in the law. Obviously not a perfect metaphor on data size, this is more about how lawsuits are more of a hassle then just giving it to them.
More like 20 years ago (sorry). 10 years ago this would have been slightly stretching, but not by much - 11x8TB raidz3. Shuckable drives would have cost $3300 (plus the chassis), and already out of the husk probably 1.5x more. So let's say $5500 total even back then. (I built my current array around the same time)
Funny, these days you could do it with 4 spindles (4x24TB raidz2) but with the rampant price inflation in storage, you're still looking at $4500.
A whopping 150GB!
And this data is 70 years of video.
Folio Photonics has just got some funding and they are saying they will be able to launch with capacities of 10 TB per cartridge.
ODA was never better than using LTO.
[0] https://pro.sony/en_GB/press/optical-disc-archive-generation...
ODA is expensive. The drives reportadly die quickly, and LTO is the animal you know. ODA only ever had one manufacturer. I believe LTO still has two or three? (IBM, HPE and maybe Quantum, but I think they are IBM).
Putting all of your eggs in one basket is never a good idea.
There were a few rumours going around that Amazon Glacier were using ODA for backups 10+ years ago, but I'm pretty sure they were just That-rumours.
This smacks of saving pennies on IT to spend dollars on lawyers.
I keep photos on Google and MS but they are short term storage only and never the only copy.
People like me who no longer pay attention enough after seeing so much upheaval in the cloud space are losing out on ideas of best practice and giving in to whatever works for the time being.
> "their vendor could effectively just decide to commit crimes"
Going bankrupt isn't inherently criminal. And IM are likely to be within their contractual rights to lock the OSS account if IM isn't being paid. > "their vendor’s vendor could just decide to compound the problem in the face of a court order is wild"
The initial court order was between "Nine PBS" and "OSS". Iron Mountain were not a party to the initial court order, and granting access without a court order naming Iron Mountain could open them up to liability from OSS.This looks like a similar formality of following the process so that a court legitimises the transfer of data back to Nine PBS.
I agree that IM is probably inside of their contractual rights, but they're still handling this in a fashion that risks causing severe issues for Nine PBS. The presence of the court order seems like sufficient inducement to at least hold the deletion until the court decides, and I'd be very curious what kinds of legal remedies Nine PBS might be entitled to should IM not do so and the court decide in their favor.
"Judge sets framework for Nine PBS to retrieve archival data"
Looks like a sensible recognition of the responsibility to restore the data and make Nine PBS, whilst recognising the cost and impact to Iron Mountain and the risks and challenges of potentially co-mingled client-data from OSS.
They weren't recording in 4K last century.
One hour of 1970's-grade NTSC video is around 300MB.
More to the point, it's not like they archived 70 continuous years of video. Many local PBS stations produce an hour or less of video each week. This being a St. Louis station, however, it's probably somewhat more.
Like most of the time, this will probably be held for some kind of extortionist legal ransom. We just love handing our stuff over to bad-faith third-parties in the name of some kind of imagined freedom. Just can't get enough of it. Public infrastructure, national archives, city services, we just seem to be completely deer-in-the-headlights when they pull this stuff on the daily...
So here we go again. We blindly trust in private parties always magically acting in good faith when there's billions on the table incentivizing them not to.
We've been doing it like this for 40 years and it hasn't worked, but I'm sure our ideological commitments will bend reality eventually.
This is your money btw.
County libraries, city hall records, large public universities.
It should have been like "hey, UNC Chapel Hill" or "Los Angeles County" take care of this.
I mean maybe things like that happen, like UTexas just loses multiple shelves mysteriously in their special collections, but I've never heard of it.
I just hate when ideological commitments shove reasonable solutions like this off the table
At that point, why wouldn't you pick a major cloud vendor? This feels like more of a governance failure.
> This unidentified vendor provided “hardware, software and cloud-storage services” for storing the public broadcaster’s archival materials and other data.
I work in several labs where I have to give this advice, which some labs are smart enough to make an ersatz backup that we store somewhere (PI's house) as a cheap offsite. Even a partial recovery is great in the face of fire/flood/explosion, or the most common error: IT fucks it up and then says "oh well".
Hope someone has some copies and they can rebuild, what a nightmare.
>This wouldn't have been an issue if the organization bought a $1,000 NAS and populated it with a few hard drives.
Look, I know that a certain percentage of Tom's Hardware articles are just sales pitches for a NAS, but this is asinine. Iron Mountain deals largely in tape storage. 50TB of tapes fits in one of their small archive boxes. If they're using the latest tech (LTO-9), it fits on 3 tapes.
This is exactly how you are supposed to store archival media for decades, not on a NAS. A NAS is for storing the files you need to actively access.
I know there would be cheaper hardware options available (I'm partial to older surplus enterprise hardware myself) but it isn't particularly reasonable to expect a small business to choose a more DIY (at least in terms of software configuration) option. You could step down to 10TB drives, but it seems unlikely they would have wanted to risk that not being quite enough.
On top of that, since 2019 is 7 years ago, it is reasonable to expect they would have had a hardware refresh at some point, I would think 5 years would be more reasonable than 3 year for something like this. At that point, the nas would be more ($1300) but the drives would be less (8 * $300), so add either another $3700 (double if both are replaced, but maybe they figured the offsite backup could be stretched even longer than 5 years)
So, rather than $2500, it would probably have been more like $8500 + OSS or $13,300 without OSS. Still that would have meant a proper are archive and a proper backup and they wouldn't be in this mess, so I completely agree with you about what they should have done, but think you were underselling the price a good bit.
Here is the source article...
https://current.org/2026/08/nine-pbs-sues-iron-mountain-over...
"Nine PBS" seems to be <https://www.ninepbs.org/>, A/K/A KETC, St. Louis, MO.
<https://en.wikipedia.org/wiki/KETC>
The upstream cited article which should be subbed in for this submission does clearly identify the station in the first line of its report: <https://current.org/2026/08/nine-pbs-sues-iron-mountain-over...>.
(I've submitted this to HN's mods via email. The original submission was to a very poor TomsHardware link.)
OT: The tendency of local broadcasters to fail to identify either on websites OR QUITE OFTEN ON BROADCASTS THEMSELVES even vaguely where they operate is ... a long-standing annoyance of mine. Sure, local audiences may know, but those passing through, or catching the signal at a distance, likely won't.
I've spent more than a few nights at higher elevations (campgrounds, highways) listening to clear channel stations reporting on weather and traffic "in the local area", sometimes for hours, without ever hearing what "the local area" is. That for signals travelling hundreds of km, and not infrequently multiple thousands of km.
(Don't get me started on entire countries where stations are identified simply by number, e.g., "Channel 4" in the UK.)
I worked at WCCO in Minneapolis briefly a few years ago. Right around that time, CBS corporate was attempting to standardize all their stations and associated websites. In their mind, that meant making everything "CBS News [Location]" and stripping just about everything else from the public marketing.
WCCO, KPIX in Los Angeles, and a few other stations battled back about this because the local name recognition of the call sign was stronger than CBS would be by itself.
So now, when you bop around the "Local News" section of the CBS Website, some cities have logos with the call letters, and some do not.
In short, when you see a station that that's difficult to identify, try finding out who owns it. Very often the ownership is to blame for one reason or another.
The United States' Federal Communications Commission (FCC) enforces specific requirements for identification that must be followed by all terrestrial radio and television stations. Stations must, when they sign on, sign off, and as close to the top of each hour as feasibly possible (such as within a "natural break" in programming, like a commercial break), present a visual (television) or aural (radio) station identification that contains, at minimum, the station's callsign, followed by its designated city of license. As a courtesy, top-of-hour identifications may also contain additional information, such as frequencies and a declaration of the station's ownership.[6] Only the name of the licensee, the station's frequency or channel number as stated on its license, and/or network affiliations, may be inserted between the call letters and station location.
https://en.wikipedia.org/wiki/Sign-on_and_sign-off#Sign-on/s... Technical information is provided. This can include station identification (call sign and city of license), transmitter power, frequency or channel number, translators used, transmitter locations, list of broadcast engineers, and/or studio/transmitter links (STL).
In my experience, the 1980s were a time when some TV stations would still sign off for a few hours, perhaps only on Sunday night. It is unusual today in the United States, for commercial radio or TV stations to sign off and sign on. When stations did sign off/on, I did hear some of them broadcasting an extended Station ID. A man's voice would call out those details listed. They would mention what mountain peak their main transmitter was on, and the wattage of "peak effective radiated power". Since I lived near the Mexican border, there were stations with Mexican licenses who broadcast in English programming, except for the Mexican National Hour. "Border Blasters", as they were called.What I distinctly recall was that it was possible to get through a full weather or traffic report without the region being identified.
These days, a frequent gripe is that local-media websites (radio and television) fail to specify the state. Where a call-sign is available, I'm obliged to look that up on Wikipedia to figure out what location the story concerns. Place names are often given only as small town or county names, neither of which typically have national recognition, and many of which repeat from state to state.