

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- I previously commented on this when a different, earlier news article and it wasn't clear at the time if the storage company was a colocation customer, or a dedicated server customer of Iron Mountain:
=============================================
(from 4 days ago)
https://news.ycombinator.com/item?id=49293326
The news article is really not clear about whether this was, relative to the company "OSS":
a) OSS is a colocation customer with its own hardware colocating it inside an Iron Mountain datacenter. In which OSS owned the bare metal and paid iron mountain for rack space and power.
or
b) OSS is a dedicated hardware customer of Iron Mountain running a service on bare metal owned by Iron Mountain, and has gone defunct, leaving behind a bunch of servers/storage arrays that would in normal circumstances get wiped/reprovisioned.
From the point of view of a customer of OSS (PBS), that's two extremely different things.
If it's scenario A, I don't see how PBS has any claim against Iron Mountain. Your typical datacenter colo host for bare metal hardware owned by a customer has no involvement whatsoever in the condition or operation of the data, operating system, filesystems, RAID arrays, ZFS, etc of how the customer has set up their environment. Nor any ability to do anything with it. A colocation host that hasn't been paid for its rack space and power will typically have clauses in its colo contracts allowing for seizure and sale of abandoned hardware after a certain period of time.
====================================
New commentary:
The new news article seems to shed a bit more light on it, it sounds like it's scenario B, in which OSS never owned the hardware (they just set up the operating system/software config on it), and was renting it from Iron Mountain. In this scenario it's much more realistic to expect to be able to get some data back. And as the new news article says, PBS is paying all of the overdue bills in order to be able to do so.
Ordinarily a dedicated server provider that is renting rackmount bare metal hardware to people has a very automated and fast re-provisioning process, if you don't pay your bill, the terms of the contract let them wipe the servers within a fairly short amount of time and reallocat them to new customers.
Now if it had been scenario A, I think that there would have been very little opportunity for judicial remedy in an order requiring Iron Mountain to do anything, because Iron Mountain would have had no control over what a failing/bankrupt/dead colocation customer did with the data on their servers. PBS might have had a claim against the principals of the OSS company, but then you get into the "blood from a stone" problem of trying to enforce a judgment against people who have no assets or ability to pay.
by walrus01 - For some reason, despite these things being rather simple and concrete distinctions, all the reporting around the case keeps being confusing, vague, and contradictory. I had been rather convinced by the Ars Technica article [1] that Iron Mountain was just the data center operator and this was colocation of completely OSS-owned and managed equipment. Iron Mountain's statements there certainly seem to say that. There's the complexity here that, in general, Iron Mountain does apparently provide both data storage, and colocation.
[1]: https://arstechnica.com/information-technology/2026/08/pbs-s...
by cge - This station was clearing over a million dollars after expenses, and they couldn't be arsed to take a backup of their data on this cloud service. I have a hard time feeling much sympathy for them. And now Iron Mountain has to referee the data being recovered without handing over others data in the process.
The utter cluelessness all around from start to finish is impressive.
by ikidd - The ruling seems fair and reasonable, and I'm surprised they couldn't come to the same conclusion without a court.by boscillator
- It’s likely that Iron Mountain needed a court order in order to do this with legal cover.
It’s just a data warehouse and OSS likely had multiple clients data and backups. Iron Mountain can’t let one third party go searching through a defunct customers stuff that has a bunch of additional third parties property intermingled with it. Too many unknowns and potentially litigious third parties.
by mikeryan - They couldn't really - I doubt Iron Mountain actually objected to giving the data, but in the end it probably wasn't in a position to know what data belonged to PBS and what belonged to other clients of OSS and you'd get very worried if a data storage company gave a companies data to someone else without authorisation.by trebligdivad
- A court is needed for cover since it is possible that sometimes else's data will be seen or even corrupted in the process. This way they can say they were doing what the court asked for. That is legal cover for everyone to do what they want. Also legal limits on what they can do.
That is how I interpret the article anyway
by bluGill - Sometimes these things can go better for companies like Iron Mountain when there's a court order/decision in place to cover them. Nine PBS, in order to access their own data, could end up accessing data belonging to other people and that may not be properly covered under existing contracts and policies. It's a risk for Iron Mountain if this happens. Having a court decision and court set procedures that essentially force them to participate and also establishes third party review of the data will give them some cover if one of those other clients of the now defunct OSS discovers that Nine PBS accessed or inadvertently retained their data.by Jtsummers
- I'm a bit confused from Iron Mountain's response about how they are worried that data could be co-mingled with other data? That would be an interesting way to back up data.by vondur
- No idea how OSS and Iron Mountain were doing things so this is pure speculation, but if for example Iron Mountain were providing an object storage platform on which OSS then ran some secondary platform that stored all the data in one place with separate metadata to figure out what's what then it's entirely reasonable that they might not be able to easily separate it out. Not saying that'd be a good way to do it, but it's easily plausible
I do something similar with my clients backups, each individual client gets their own bucket on B2 for many obvious reasons but to sort out anything beyond what's obvious from the bucket name you need the backup software and appropriate encryption keys.
by wolrah - Iron Mountain probably only knows what data was owned by Open Source Storage, but not on the level of which data belongs to which Open Source Storage customer.
If so, it would be incredibly reckless for Iron Mountain to provide all of the data stored by Open Source Storage to one of Open Source Storage's former customers (PBS). Presumably that is why they wanted to go through the legal process so that someone else would be vested with the legal authority to determine what data PBS can legally access.
by cyphar - Earlier coverage (St. Louis KETC / Nine PBS sues Iron Mountain for data access):
"Nine PBS sues Iron Mountain over blocked access to archival data" <https://news.ycombinator.com/item?id=49285418>
This is working out largely as I'd suggested it should, albeit with a court's intervention. See: <https://news.ycombinator.com/item?id=49293058>.
I'd still argue that I.M. should have anticipated this situation, and have some process in place to address it. "See a court" might well be part of that process.
by dredmorbius - The court got this right. This is when you need a special master to help with cleanup after a bankruptcy.
We saw something like this when TechShop went bankrupt, with member property in storage on the premises. The bankruptcy trustee set up a procedure where former members could make an appointment to retrieve their property, escorted by a representative of the trustee. Huge pain, but necessary.
by Animats - > William Cravens, the attorney representing Iron Mountain, told the judge his client doesn’t know the format of Nine PBS’ materials that were stored by OSS. He expressed concern about whether Nine PBS’ archival material is lumped together with data from other OSS clients. Iron Mountain wants to avoid potentially corrupting the other data, Cravens added.
> Elliff ordered the immediate return of any physical devices that hold Nine PBS’ data once access to OSS’ storage system is granted…
> Once Nine PBS retrieves its data, the station must work with a third party to ensure that no data from other OSS customers is among those materials.
I don’t love this call. Handing over any disk has several problems. It could easily contain very sensitive data from another client. It’s inherently one-sided (another client can’t make the same request if the disk is already gone). And it’s being handed over to a PBS station that doesn’t seem to have the technical chops to manage data backups/security.
I want them to get their data back, but this needs a technical intermediary that handles all client data equally.
by scosman - Open Source Storage (OSS), the vendor in question, was around for two decades before going out of business last year. The first and last archived versions of its web site:
https://web.archive.org/web/20040628023451/https://www.ossto...
https://web.archive.org/web/20250329140721/https://www.ossto...
(The first version isn't too exciting. It's a broken Flash site.)
by js2 - I think stories like these highlight the need for clearer (not necessarily more) regulations around contractor/subcontractor/client relationships and what happens when one of them goes tits up.
There were rampant issues in the fintech world that exploded when Synapse, a banking as a service provider, went bankrupt and their ledger didn't match what partner banks had in their accounts. End users were told "your deposits are FDIC insured", but in bankruptcy court the judge was sort of at a loss over how to rectify things - the banks weren't insolvent, and the FDIC (rightfully) said "hey, this isn't our problem, our regulated entities are in compliance". Looks like a similar situation happened here, where the contractors are both doing the "not it" thing.
I feel like a lot of tech innovation and "business process innovation" over the past 15 years was just ignoring regulations that were built up over decades, only discovering the reasons for those regulations when the tide went out and seeing that lots of companies had been pantsless the whole time.
- If you talk to a lawyer (or, worse, a legislator, many of whom are also lawyers and all of whom are surrounded by them), they will insist up and down that this is a pretty standard custodial arrangement dispute and that the system worked as intended. And I would, very begrudgingly agree with that.
The legal system is perfectly capable of recognizing stolen property no matter how many layers of abstraction you put it through. The problem is always in the fact that the dispute resolution process is too expensive[0] to be useful. If you are defrauded for $10,000; but the legal fees for your representation will exceed that; then that juice ain't worth the squeeze. See also: Bricks and Minifigs.
In the Nine PBS case the judge correctly recognized Iron Mountain as a constructive bailee of Nine PBS's property and created a framework to retrieve their data. The problem is that this took almost half a year of legal work to get to the obvious outcome to make Nine PBS whole.
In Synapse's case, the problem is slightly different, because Synapse is not a bank, they are a reseller of banking services. That's the whole idea behind "fintech[1]" - that we can sell banking services while dodging all the regulatory compliance designed specifically to stop these kinds of issues so long as a real bank is involved. Saying their deposits are FDIC insured is like saying you have auto insurance because you happen to be riding a taxi. Technically correct but misleading and fraudulent. FDIC insurance doesn't cascade into your customers' accounts, because if it did, you'd be a bank.
[0] There's a similar problem with Bitcoin, where only a certain number of transactions can ever be processed per hour and thus it bottlenecks any higher-layer process that intends to use the Bitcoin blockchain as a settlement or dispute resolution system.
[1] "Fintech" in particular is meaningless as all banks are tech companies. They were one of the first adopters of electronic computers, online transaction processing, and a whole load of other things that seem utterly quaint now.
EDIT: changed "years" to "almost half a year", I was too lazy to do another Google search
by kmeisthax - Why do you think the laws and regulations are unclear?
This seems to be following the completely standard and expected process.
Contractor goes belly up, so you go to court and a judge who confirms they were a custodian of your data and you are entitled to retreive it.
Same would be the case if I was leasing equipment to someone and they had it at a storage lot. If the middle party dies or goes bankrupt, I get a court order to claim it from their other possessions.
- "your deposits are FDIC insured" claim was a lie, for anyone building on top of Synapseby tintor
- > … was just ignoring regulations that were built up over decades, only discovering the reasons for those regulations …
yeah it’s unreal to me how many people who imagine themselves intelligent are just now discovering the equivalent to why we make wheels round.
they never think to ask “why does regulation x exist?”
its absolutely crazypants.
by toofy - Whoever claims "your deposits are FDIC insured" needs to be prosecuted as fraud and scam artists. “Your” the company’s deposits in the bank is FDIC insured. My deposit with you the company is not. When the bank goes belly up, your deposit is FDIC secured up to the account limit which is tiny in the scale of things. When your company goes belly up, my deposit is gone.by ww520