A Dead Vendor Is Holding 70 Years of PBS Footage Hostage
Nine PBS's 50TB archive sits intact in a Denver data center it can't legally touch.
The headline making the rounds says a PBS station "lost" 70 years of television history when its cloud storage vendor went under. That's not quite what happened, and the real story is worse. The data — more than 50TB of archival footage belonging to Nine PBS, the St. Louis member station — is almost certainly sitting intact on servers in a Denver data center right now. Nobody deleted it. The station just can't touch it, because the company it paid to store it, Open Source Storage, stopped answering emails, let the contract lapse on March 6, cut off access without honoring the agreed 30-day retrieval window, and then effectively ceased to exist. Its website went dark and its Colorado business registration lapsed into delinquency.
Here's the part that should make you sit up: the servers live in a facility run by Iron Mountain Data Centers. Iron Mountain initially signaled it would help, then reversed course and refused to hand anything over — because its customer is OSS, not Nine PBS, and the hardware belongs to OSS. Nine PBS won a default judgment in St. Louis Circuit Court confirming it owns the data, then had to file a second suit in Denver in late July just to get a court order preventing the drives from being wiped or overwritten. A judge granted that temporary relief; a hearing was on the docket this week. Iron Mountain hasn't commented publicly.
Your vendor's vendor doesn't know you exist
Strip away the archival-footage pathos and this is a subprocessor problem, the same one lurking under half the SaaS contracts you've signed. Nine PBS thought it had a cloud storage provider. What it actually had was a thin reseller — a company providing "hardware, software and cloud-storage services" since 2019 — running its own boxes in someone else's colocation facility. The party with physical custody of the bytes had no contractual relationship with the party that owned them.
That gap is invisible when everything works. When the middle layer dies, it becomes the whole story. Iron Mountain's position — we host OSS's servers, OSS owns the servers, take it up with OSS — is legally coherent and operationally useless, because OSS is a shell with a defunct website and a default judgment against it. A judgment against a dead company recovers nothing. That's why the litigation had to chase the data to Colorado, where the drives physically are: possession turned out to matter more than ownership.
If you're evaluating any storage or backup vendor smaller than a hyperscaler, the question to ask isn't "are you SOC 2 compliant?" It's "who physically holds my data, and what happens to my access if you stop paying your bills?" A compliance report attests to controls; it says nothing about corporate mortality. If the answer involves colo cages and vendor-owned hardware, your data's availability is coupled to that vendor's solvency in a way no SLA addresses.
We've watched this movie before
None of this is novel. Nirvanix, a venture-backed cloud storage provider with real enterprise customers, collapsed in 2013 and gave clients roughly two weeks to evacuate petabytes — a physics problem as much as a business one, since you can't push petabytes through a WAN link on that timeline. Megaupload's 2012 seizure stranded legitimate users' files on hosted servers for years; one videographer, Kyle Goodwin, spent the better part of a decade in court trying to recover his own footage from hardware caught in someone else's legal mess.
The pattern is stable across all three cases: the data survives, access doesn't, and the recovery path runs through courtrooms instead of consoles. Cloud storage marketing sells durability — the eleven nines, the erasure coding, the multi-region replication. Durability was never the failure mode here. Continuity of access is a legal and financial property, not a technical one, and no amount of RAID fixes a counterparty going dark.
50TB is three hard drives
The detail that turns this from unfortunate to indefensible is the size. Fifty terabytes is not big data. It's three modern hard drives. It's roughly $1,100 a month in S3 Standard, or about $50 a month in S3 Glacier Deep Archive. A full second copy of this archive — the entire recorded institutional memory of a 70-year-old broadcaster — could have been maintained for less than the cost of one employee's health insurance.
The 3-2-1 rule (three copies, two media types, one offsite) is preached to death precisely because organizations keep treating "it's in the cloud" as if it satisfied all three numbers at once. It satisfies one. A single copy with a single custodian is a single point of failure regardless of how durable that custodian's storage layer is, and Nine PBS is now demonstrating the failure mode in two courthouses simultaneously.
For anyone responsible for data that must outlive vendor relationships, the practical checklist writes itself:
- Run egress drills. Actually restore, on a schedule, with a tool you control — rclone against an S3-compatible endpoint, or whatever fits your stack. A retrieval path you've never exercised is a hypothesis, not a capability.
- Put exit terms in the contract, then assume they're worthless. Nine PBS had a 30-day retrieval clause. OSS simply ignored it, and there was no one left to sue who mattered. Contractual exit rights are necessary and insufficient; the redundant copy is what actually protects you.
- Map the custody chain. If your vendor resells someone else's infrastructure, get the sub-provider named in writing, and understand that your rights against them are approximately zero.
- For true archives, own a copy on media you control. LTO tape or offline drives in your own facility. Boring, cheap at this scale, and immune to anyone else's bankruptcy.
The uncomfortable verdict
It's tempting to file this under "small vendor risk" and conclude the lesson is just use AWS. That's half right — a hyperscaler's bankruptcy isn't a realistic threat model, and consolidation onto boring infrastructure genuinely would have prevented this. But it dodges the deeper point. Account lockouts, billing disputes, government seizure of shared infrastructure, and abrupt product shutdowns all produce the same effect as vendor death: intact data you cannot reach. The hyperscalers reduce the probability; they don't change the category.
Nine PBS will probably get its archive back — the court has already frozen the drives, and ownership isn't seriously in dispute. But it will have spent a year and serious legal fees recovering data that three hard drives in a closet would have made a non-event. That's the ratio to remember the next time a redundant copy feels like an unnecessary line item.
Sources & further reading
- PBS broadcaster loses access to 50TB of data after cloud storage vendor goes defunct — tomshardware.com
- Nine PBS sues Iron Mountain over blocked access to archival data — current.org
- Missouri PBS station sues vendor after video archive becomes lost — thedesk.net
- PBS Station Sues to Regain Access to 70 Years of Archival TV History — gizmodo.com
Ji-ho covers the increasingly tangled overlap between cloud architecture and security, drawing on a background as a penetration tester to keep his reporting grounded in real-world attack paths. He never lets a vendor claim go unquestioned and insists that every buzzword come with a proof of concept.
Discussion 0
No comments yet
Be the first to weigh in.