LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-31-2014, 04:58 PM   #16
brian@fodvo.org
LQ Newbie
 
Registered: Mar 2014
Posts: 1

Rep: Reputation: Disabled
I like SpiderOak -- but


I've used Spideroak for a year or so, and believe for a single device its quite secure. But there is a gap that I haven't figured out a work-around yet.

Let's say you have 2 devices to backup, a laptop that doesn't contain too much secret info, and a home desktop that contains much more secret info. If both devices are on the same account, theft/loss of your laptop could very easily mean the compromise of your secret data from desktop as well, because both devices can access all files.

The web site has a FAQ to suggest to de-register the lost device and change password. But there is a natural time gap before you can accomplish this. A gap that could result in data compromise.

Double encryption of the secret data is an option, probably the best, but you'll need to work up some scripts to accomplish.

Just be nice if there was a way to isolate devices, with perhaps a master key access.

Or two accounts.
 
Old 04-01-2014, 04:09 AM   #17
exceed450
Member
 
Registered: Feb 2013
Posts: 37

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by brian@fodvo.org View Post
I've used Spideroak for a year or so, and believe for a single device its quite secure. But there is a gap that I haven't figured out a work-around yet.

Let's say you have 2 devices to backup, a laptop that doesn't contain too much secret info, and a home desktop that contains much more secret info. If both devices are on the same account, theft/loss of your laptop could very easily mean the compromise of your secret data from desktop as well, because both devices can access all files.

The web site has a FAQ to suggest to de-register the lost device and change password. But there is a natural time gap before you can accomplish this. A gap that could result in data compromise.

Double encryption of the secret data is an option, probably the best, but you'll need to work up some scripts to accomplish.

Just be nice if there was a way to isolate devices, with perhaps a master key access.

Or two accounts.
I find it very very weird if they want you to use the same private key on both computers, thats just bad design in my opinion, but the password for the private key should expire after a period of time i would believe and if not that too is really poor design, you should have to re-type the password for the private key after some period of time has passed...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Has anyone used spideroak cloud storage? bashscript Linux - Virtualization and Cloud 2 11-25-2013 06:46 AM
[SOLVED] Installing SpiderOak on Debian 7 AndyInMokum Linux - Newbie 2 08-16-2013 01:32 PM
[SOLVED] SpiderOak on Slackware 14.0 agripp Slackware 3 07-01-2013 01:50 AM
LXer: SpiderOak: Cloud 9 LXer Syndicated Linux News 0 07-30-2011 05:21 AM
LXer: Spideroak: Secure Offsite Backups For Linux LXer Syndicated Linux News 0 01-23-2009 07:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration