LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-11-2017, 09:08 PM   #1
rblampain
Senior Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Debian 11
Posts: 1,288

Rep: Reputation: 52
how can I avoid backups in the clear?


Having just discovered the existence of hardware encryption (SED SSD) which I like, I also found that stealing a laptop whose SSDs are self-encrypted becomes far less tempting than stealing a backup of that/those drives which will be in the clear (for the CPU to process) and easier to physically access. How could those backups be protected? (I anticipate there must be a generally-accepted solution to this). Or is it necessary to backup to external SED SSDs?
Are "Internet" backups a good option? (Backing up to an external site of SED SSD on the Internet.)

Thank you for your help.
 
Old 12-11-2017, 09:27 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,324
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
I prefer to do my backups locally; I point them to external media, that is, hard drives attached to other computers or external hard drives which do nothing but hold backups.

The important thing about backups is this: if they are not to external media, they are not backups, they are replications.

I am not a fan of third party "clouds." If they are not under my control, I will not blindly trust them. I am a cynical old curmudgeon, but I find that too many outfits have based their business models on selling user data for profit.

Of course, if you have a secure VPS out there somewhere, one that is under your control and from a trustworthy provider, that could be an option, but, if it's third party, remember that it could go away at any time.
 
2 members found this post helpful.
Old 12-11-2017, 09:49 PM   #3
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,128

Rep: Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120
Simplest would be an external SED.
However once the data is read off the (encrypted) source drive it is in the clear - over the bus, into memory. If you have a compromised machine, all your efforts will all be for naught. Not likely maybe, but possible.
I would go with the external SED - the exposure is (extraordinarily) low and the benefits significant. I don't use cloud based options, but that is personal choice.
 
1 members found this post helpful.
Old 01-09-2018, 08:37 AM   #4
tocii.
LQ Newbie
 
Registered: Jan 2018
Distribution: Ubuntu, Mint
Posts: 27

Rep: Reputation: Disabled
I think the best is when you write a simple bash script for backup with rsync.
You can save your files to a remote host or a Mounted disk/s.. or where you want.
 
1 members found this post helpful.
Old 01-09-2018, 09:08 AM   #5
hydrurga
LQ Guru
 
Registered: Nov 2008
Location: Pictland
Distribution: Linux Mint 21 MATE
Posts: 8,048
Blog Entries: 5

Rep: Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925
I personally back my data up to a container on an external HDD which is encrypted with VeraCrypt. If anyone manages to steal the external HDD, good luck to them.
 
1 members found this post helpful.
Old 01-09-2018, 11:15 AM   #6
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Backup software can usually encrypt the files that it saves to the backup volume.

The backup daemon should also run as a user which has access to the files that are to be backed-up but that writes the data to a directory that only it can access. Other system users should not be allowed to access the backup repository, much less alter anything on it.

In my view, encrypting the volume is primarily geared at making a stolen laptop useless. Stolen laptops have been found thrown away in airport trash-cans with the hard drives taken out. The industrial spies (presumably) only wanted the data and maybe the SSL keys.

Last edited by sundialsvcs; 01-09-2018 at 11:16 AM.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
XSIbackup - do backups overwrite existing backups robertkwild Linux - General 3 11-14-2020 09:33 AM
Switching from dump tape directory backups to NAS disk backups on RHEL 6 Jerry_C Red Hat 0 06-05-2013 12:44 AM
clear is hashed (/user/bin/clear) What does it mean? mohammed.hossain Linux - Newbie 1 10-24-2010 07:53 PM
Series of rsync backups over SSH - avoid multiple logins Meson Linux - Server 1 04-25-2008 07:21 AM
How to clear a std::string buff.clear()? lucky6969b Programming 3 03-17-2006 07:50 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:26 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration