3 ms·
BackBlaze's lax approach to security and unreasonable requests for what data I should provide for them to debug a bug in their client is why I switched to Crash
by timcederman 9y ago
BackBlaze's lax approach to security and unreasonable requests for what data I should provide for them to debug a bug in their client is why I switched to CrashPlan.
(said bug also caused me to exhaust my 1TB Comcast cap several months in a row, BackBlaze was unresponsive and unapologetic throughout the whole process)
- cryptarch 9y agoDo you happen to know if CrashPlan's encryption is any better? AFAIK AES in CBC-mode is a no-no because it betrays which blocks of data are identical, and that's what BlackBlaze uses.
- timcederman 9y agoWithout inspecting the system, hard to say for sure, but on paper it's much better. https://support.code42.com/CrashPlan/4/Configuring/Security_Encryption_And_Password_Options https://support.code42.com/CrashPlan/4/Configuring/Security_... I really liked the fact that I could set my own key too.
- rocqua 9y agoThat is not the case. That would be ECB mode. CBC stands for cipher-block-chaining. Where you xor the plaintext with the ciphertext of the last block before encryption specifically to prevent identical blocks from yielding identical ciphertext. There are some issues with CBC regarding the fact that it can't really be parralelized. It also lacks authentication as opposed to the newer GCM mode. In general though, AES-256 CBC is essentially THE standard best practice proven form of encryption.
- cryptarch 9y agoOh, thanks for the info, I mixed those up.
- cookiecaper 9y agoBackblaze has repeatedly refused to add something as simple as pagination to their B2 web interface, a feature that takes less than an hour to implement and which most people would not dream of going live without, and their support people are terse and uncooperative. I've more or less stopped using them for this reason. They have a lot of employees who read HN and I'm sure they're cool guys, but I think they really need to reconsider their performance in customer experience.
- brianwski 9y agoBrian from Backblaze here. > Backblaze has repeatedly refused to add something as simple as pagination to their B2 web interface Not "refused to add", it's on the list! We have a relatively small team of programmers (no VC funding, no deep pockets, we can only hire when we can afford it), and every week we meet and set priorities and the engineers work on the very highest priority stuff in order. The pagination has been delayed in favor of other features and bug fixes. I'm not saying we prioritized correctly, I'm just explaining why it has not been done yet. > which most people would not dream of going live without Part of the challenge (fun?) of building a business is the "build order". We don't make any money until we release the product, so as soon as we can justify it we released it in "paid beta" to collect feedback like yours and make some money which in turn allows us to hire one more programmer and build that feature for you. If B2 doesn't fit your needs yet, my only request is that you come back every six months and check again, because it is always evolving.
- cookiecaper 9y agoThanks for the reply. I didn't know that Backblaze was bootstrapped and I really do respect that. But this has been "on the list" for about a year. For an object storage offering, crashing the tab whenever someone opens a large bucket is not something to brush off. I was initially sympathetic, but since B2 also does not have an API call that will allow me to update my filenames (either 'rename' or 'copy to new name') to comply with the "virtual folders" feature, which either didn't exist when I wrote my script or which I overlooked, I'm stuck. I asked support to make a bigger push to get some simple pagination added and they said they'll register the feature request. I emphasized that this isn't just a convenience feature, but that it actually makes the tab too slow to use and/or crashes it (don't remember which right now to be honest), but it didn't matter. I asked support to make a one-time exception and find someone who could run a find and replace on the object filenames to comply with the new name structure and they declined to do so. The only option is to pay to download the incorrectly-named files and reupload under new names, which would cost a lot of money in download fees, not to mention a lot of clock time and bandwidth. Of course, this isn't really intractable. To avoid extra charges from Backblaze, I could just upload the files again since I still have a local copy (for now), but that would also take a lot of time and bandwidth. I could write a client-side script that would stop the B2 interface's broken behavior, and that would make the bucket semi-browseable/usable via the web. But I just don't feel a need to do all that when I could use other solutions that are better about this kind of thing. B2 left beta a while ago iirc.
- tyingq 9y agoCrashPlan's custom key seems similar: "Web restore key access - You must supply your custom key in order to restore files"[1] [1]http://support.code42.com/CrashPlan/4/Code42_App_Reference/Security_Settings_Reference http://support.code42.com/CrashPlan/4/Code42_App_Reference/S...
- subsection1h 9y agoThat is CrashPlan's web restore process.[1] Consider reading The Wirecutter's comparison of CrashPlan and Backblaze[2] to better understand the (significant) differences between these two services. [1] https://support.crashplan.com/Restoring/Downloading_Files_From_The_Web https://support.crashplan.com/Restoring/Downloading_Files_Fr... [2] http://thewirecutter.com/reviews/best-online-backup-service/ http://thewirecutter.com/reviews/best-online-backup-service/