5 ms·
It's rough out there and has become increasingly difficult to maintain our pace of storage deployment. Further - and most concerning - is the pollution of the
by rsync 11mo ago
It's rough out there and has become increasingly difficult to maintain our pace of storage deployment.
Further - and most concerning - is the pollution of the supply chain with refurbished/recertified stock being sold and marketed as "new".
One example:
https://kozubik.com/items/MaestroTechnology/ https://kozubik.com/items/MaestroTechnology/
I strongly advise buyers to stick with trusted suppliers, avoid Amazon/ebay channels, and carefully vet your incoming stock with SMART tools to ensure you receive what you think you are ... especially for SSD parts.
- kkylin 11mo agoQuestion for all of you more knowledgeble than I: can SMART data be tampered with? When I get, say, a refurbished Mac from Apple, I'm trusting Apple won't stoop to that. But a SSD vendor I've never heard of?
- fny 11mo agoYes, it can be tampered with. Drives can even lie about the amount of storage they support. I once bought a 1TB pen drive that was only 32MB for $10. (Yes, I knew it was a scam beforehand.)
- goopypoop 11mo agobetter than 10 floppies!
- rsync 11mo agoYes. There are vendor-specific utilities that have escaped into the wild that allow bad actors to reset various SMART counters, etc. A lot of abuse came to light during the launch and initial mining of the (ridiculous) Chiacoin[1] during which Chia miners would burn through SSDs to within a hair of their usable life, reset their SMART stats, and sell them as new on Amazon or ebay. As can be seen in my above comment, larger distributors like "Maestro Technologies" have their stock polluted with parts like this and I find it very unlikely that they are not aware of the status of these parts they are selling as new. [1] https://en.wikipedia.org/wiki/Chia_Network https://en.wikipedia.org/wiki/Chia_Network
- ikiris 11mo agoTrivially
- estimator7292 11mo agoDO NOT assume SMART is reliable. You can wipe SMART stats or write any values you want. You have to actually examine the real bits on the drive. Resellers don't want to take the time to actually zero a drive, they usually just nuke the partition table. You also need to physically examine the drive. Corroded fingerprints on the PCB, wear on the port contacts, scratches from mounting rails, etc. That's how it found out that the last "new" drive I bought on Amazon was actually a used Backblaze drive. It contained terabytes of customer data, and a shit ton of cleartext files. SMART, of course, reported it was a brand new drive with zero hours. Cleartext logs on the drive showed many thousands of hours of runtime. Physical examination is the only reliable method.
- neilv 11mo ago> That's how it found out that the last "new" drive I bought on Amazon was actually a used Backblaze drive. It contained terabytes of customer data, and a shit ton of cleartext files. SMART, of course, reported it was a brand new drive with zero hours. Cleartext logs on the drive showed many thousands of hours of runtime. This sounds like it could be a big problem for Backblaze customers, and consequently for Backblaze. Can you alert the Backblaze CEO about their insufficiently-decommissioned drives leaking out like this? Backblaze customers also need to know, but I would give Backblaze the first shot at figuring out how to notify, whom, of what.
- prirun 11mo agoBackblaze erasure-codes customer data across 17 (I think) servers, so customer data is probably not accessible. Yes, it would be better if they zeroed the drive, but Google says that will take 14-30 hours for a 10TB drive. For drives that implement an internal encryption key, it's faster (instantaneous) to reset the encryption key. It won't give you a zeroed drive, but one filled with garbage.
- neilv 11mo agoThe earlier description is ambiguous (i.e., is it data of or about customers, and is that data cleartext), but it seems they believe they have a drive from Backblaze with a lot of cleartext files on it, and something involving customers. > It contained terabytes of customer data, and a shit ton of cleartext files.
- catigula 11mo agoNearly any product you can buy from Amazon, even when it says shipped from Amazon, is suspect. I wouldn't shop there at all. It's a literal scam market. Allegedly.
- bdcravens 11mo agoI've never considered myself very paranoid about Amazon, but recently I needed a cheap router, but couldn't shake the feeling that I shouldn't get it there (went with an in person Best Buy purchase instead)
- tracker1 11mo agoI'm using an N305 mini pc with OpnSense for my router, with a separate commercial AP for wireless... generally working very well/stable.
- tracker1 11mo agoI try to stick to at least "sold by amazon" as much as possible, that or the mfg. Generally, even with comingled inventory, Amazon has been good about replacements/refunds.
- hulitu 11mo ago> avoid Amazon/ebay channels, But why ? They are the good ones. TEMU and Shein bad. /s
- PeterStuer 11mo agoI have given up on Amazon and similar "market makers" (bol.com is a regional one here) completely. Too much fraud. Instead I use specific vertical or store as sourced outlets.