5 ms·
What has put me off Tarsnap was not realizing that the price per GB is for compressed storage. So while it looks high compared to Amazon's per GB pricing, it's
by read 13y ago
What has put me off Tarsnap was not realizing that the price per GB is for compressed storage. So while it looks high compared to Amazon's per GB pricing, it's a lot cheaper.
I don't recall if this was on Tarsnap's website when I had first checked, but it might be worth reporting the average compression rate to make more visible to prospective customers what the Amazon S3 storage portion of the pricing is.
- pedrocr 13y agoI'd assume the average compression rate to be very low, no? Don't modern cryptosystems have to encrypt then compress to avoid some forms of attack, thus making the compression not very effective?
- deleted 13y ago[deleted]
- amalcon 13y agoThose attacks only work when the attacker has some control over the plaintext. Backup services don't have that problem.
- pedrocr 13y agoSo tarsnap compresses then encrypts?
- amalcon 13y agoI haven't actually checked that; all I mean to say is that it would be relatively safe to do so.
- JW_00000 13y agoYes. And it de-duplicates as well.
- mpyne 13y agoGuys, don't confuse the crypto issues here. The whole point to tarsnap is to be able to safely encrypt any and all of your data, including compressed data. We wouldn't expect that a .tar.gz being backed up is somehow "less secure" than the .tar file, we'd demand the same security for both. Compression becomes a problem when it can be used as an "oracle" into the key used for a given stream of ciphertext. The reason TLS is susceptible is because the attacker can MITM and control at least some aspects of the plaintext or shared client-server state, and iterate repeatedly to refine their guesses. These issues simply don't apply in the same way to backing up files. I sure there are still theoretical issues that would need to be worked through in deciding how you'd do something like this, issues which could be better explained by any of the many crypto types who hang out here. But don't cargo cult your treatment of crypto.
- deleted 13y ago[deleted]
- solarexplorer 13y agoWell, if you backup your entire disk, then there is probably a fair amount of known plain text...
- nitrogen 13y agoIn the recent web attack instances, it's not just known plaintext, it's using compression to discover unknown plaintext by repeatedly guessing across multiple requests and watching for the request size to change. So an attacker would need the ability to alter your filesystem and make backup requests, repeatedly, for that attack to matter to Tarsnap.
- anton_gogolev 13y agoI'd wager that the output from "modern cryptosystems" is, for all practical purposes, not compressible at all.
- midas007 13y agoA strong construction should be impossible to compress because encryption maximizes bit entropy, which should make the cyphertext indistinguishable from a PRF (ie a random noise source). MAC, decrypt, decompress.... always^9 in that order.
- pedrocr 13y agoRight, encrypt then compress is useless. And compress then encrypt is unsafe in some cases[1]. Apparently backup isn't one of them, you need to be able to choose the plaintext. https://en.wikipedia.org/wiki/CRIME_(security_exploit) https://en.wikipedia.org/wiki/CRIME_(security_exploit)
- mnutt 13y agoWhat if tarsnap released a command-line tool that could be run on a directory to estimate its storage cost, pre-signup?
- hamburglar 13y agoYeah, I almost wrote to them suggesting exactly this, but then I figured what the heck, I'll just sign up. The tool would definitely be helpful, though.
- late2part 13y agoNot really. If you compressed your data on Amazon, you'd get a lower per-GB price too. I think tarsnap is good, and you're paying him for the service of interfacing to Amazon for you. It's not accurate to say his price of compressed storage is comparable to uncompressed storage.