3 ms·
Do your daily backups using rsync+hardlinks (rsnapshot, dirvish or something similar) and keep a long history. This is slower than copy-on-write ZFS (obviously)
by abbot2 14y ago
Do your daily backups using rsync+hardlinks (rsnapshot, dirvish or something similar) and keep a long history. This is slower than copy-on-write ZFS (obviously), but works reliably on any Linux/Unix file system and the storage cost is roughly the same as for ZFS.
- raphinou 14y agoThis is kind of what I'm doing as backups, but I still don't feel safe (I'm kind of paranoid for my backups):what if an attacker gets in your server and wipes out all your data and backups? And you know Murphy is always ready to strike... I'm currently looking at making regular backups offline, on DVD or blue ray disks, and automating the process. I wonder if this might be a service people are interested in. Let me know what you think... (I put a landing page at http://www.offlinebackups http://www.offlinebackups to test reactions)
- abbot2 14y agoIt is never a good idea to keep backup copies at the same place as the source data, so normally it should be not that common for an attacker to be able to wipe both original and backup. Regarding the offline optical disc backups, they are still ridiculously expensive compared to magnetic spinning drives or tapes. Backup, especially an automated one, is always an extra security risk to consider, but apparently there are no other good ways...
- raphinou 14y agoA lot of people put their backups on S3, with a script running on the server. Even if you limit the rights with IAM to only put files, the attacker can overwrite existing files on S3. The only way I thought to prevent that is to give only write access with no listing access, and append a random number to the file name. But, who does that? I'm sure 90%+ of the servers backing up on S3 are not safe for this scenario. The reason I thought of DVDs is that they're not sensitive to electromagnetic fields as disks and tapes. (You never know: http://www.telegraph.co.uk/science/space/9097587/Solar-flares-everything-you-need-to-know.html http://www.telegraph.co.uk/science/space/9097587/Solar-flare... )
- andrewf 14y agoIf you turn on file versioning in S3, then you'll be able to get to the data that was "overwritten". I don't think there's a way for someone with only PUT access to work around this.
- zobzu 14y agoI making backups using duplicity with incremental backup option, which is basically librsync, and would allow such restores (as incremental = diff) Not sure why it's not used "more". The tool is pretty straightforward.