Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

50% Positive

Analyzed from 1450 words in the discussion.

Trending Topics

#backup#data#storage#hard#devices#files#drive#nas#sync#offline

Discussion (25 Comments)Read Original on HackerNews

bblbabout 2 hours ago
One thing I would add to a modern backup strategy: a deferred offline copy

Sure it's bothersome to use the sneakernet once a month (manually copy data to USB stick and stash it somewhere), but when that ransomware hits (can happen on personal devices also), it literally can't access the offline copy, and try to encrypt that one also.

Immutable backup solutions are code and thus eventually defeatable from the remote attackers point of view. Offline requires physical access, and maybe a big enough wrench to get the USB stick's disk encryption PIN out of you.

dataflow6 minutes ago
[delayed]
bob1029about 1 hour ago
Tape + Iron Mountain is difficult to beat for offline copies.

Surrendering just a little bit of absolute control over the physical media can dramatically increase the likelihood that it survives whatever apocalyptic event. I don't know that I've ever heard of tapes being stolen from Iron Mountain. Even if this happened, what are the odds that they would get all the tapes. Your tapes? It probably looks like the warehouse from Raiders of the Lost Ark in there.

microtonalabout 1 hour ago
Immutable backup solutions are code and thus eventually defeatable from the remote attackers point of view.

Yeah, but an attacker is unlikely to compromise both you and your storage provider at the same point. Many S3-compatible storage providers (e.g. Backblaze and Hetzner) support object lock, where you can lock objects for a certain number of days (and refresh locks if the objects are still used in recent backups). Typically object locks are implemented such that not even you yourself can remove the data from the account settings.

E.g. when I cancelled my Backblaze B2 account, I had to wait until the object locks expired before I could remove the remaining data and delete the account.

Arq on macOS has great support for object locks BTW.

BLKNSLVRabout 1 hour ago
I have a locker at my place of work where I store a few HDDs and USBs. These are the most up to date, but I also have others at my parents place and my in-laws. Gets troublesome keeping track of which ones are up to date as of what date. Good challenge for staying organised though, I've got a whole naming system and numbered hierarchy and scripts that run ordered by priority.

Well overdue for a refresh.

fc417fc802about 2 hours ago
> One of the other materials that I could not figure out how to back up properly is emails. The reason is that there is no clear way to back it up systematically

Doesn't that depend entirely on the storage format? For example if you use thunderbird as a client it has database files that you can copy. Since you say that one of your devices is running arch you should check out some of the email options in the repos. There are at least a few of options that can act as a middleman to bridge between your external accounts and your clients.

> So having a plan to roll back to a stable state might be helfpul. I installed and set up Timeshift for this

Snapshots make this trivial. Particularly in the case of btrfs if you configure your bootloader to always use the default subvolume then rollback becomes just `btrfs subvolme set-default`.

TranquilMarmotabout 1 hour ago
I have a server in a closet with a few hard drives attached to it. All of my devices connect to it via Tailscale.

I use the wonderful https://github.com/garethgeorge/backrest as a web UI around restic.

Every night, I back the data up to a Hetzner storage box https://www.hetzner.com/storage/storage-box/ which is only ~$3.50/mo USD for 1TB of data.

I have three "tiers" of data for myself:

1. Important things I care about: these go into a folder that gets backed up to Hetzner (examples include photos in Immich, code pushed to Forgejo, etc)

2. Smaller files I sort-of care about: these usually just go into Proton Drive (examples include design documents)

3. Large files I don't care about losing: these go into a folder on a hard drive that is not backed up (examples include media)

This took me about a day to set up and I just check in on it every once in a while. Once a year I will do a practice disaster recovery run.

martin-about 1 hour ago
What does your practice recovery run look like? I've got backup set up, but I don't know how to best test it. For example, do you restore everything from Hetzner, or some random sample?
microtonalabout 1 hour ago
I don't like these staged backup for these reasons. Every step (e.g. NAS backup to Hetzner) can cause an error, so adding steps increases the probability of error. Personally, I just back up directly from my machines to a local storage server and to a cloud object storage with object lock (so that e.g. ransomware encryption or attempts to remove the data do not work).
akerstenabout 3 hours ago
What the author describes here is hard because it's "simple."

What's simple because it's "hard" is replacing parts 2 & 3 with a network appliance like TrueNAS running a zfs pool that syncs to backblaze every night. Yeah you have to learn a bit but it won't fall in weird ways like the hard drive part here will just fail to mount one night and not back things up for 3 months until you notice. My 2¢

fc417fc802about 2 hours ago
> like the hard drive part here will just fail to mount one night and not back things up for 3 months until you notice

I think the author is having trouble because he is conflating concepts and roles that should be distinct. Sync, rotating snapshots, and deduplicated backups need to be kept entirely separate if you want any hope of maintaining your sanity.

So he's got sync but he's missing some sort of rotating snapshot system which would solve the stated concern of guarding against syncthing replicating corrupted data. Such automated snapshots can then be used as the source to feed the backup pipeline.

That hard drive doesn't make a good backup because it seems that it is always online. You need an offline backup that you manually plug in to run the job once every so often.

He's also making this more difficult than it needs to be by insisting that the backup drive be compatible with windows. Plug the drives for both snapshots and backups into a linux box, format them with a modern filesystem, and get on with life.

Sync is its own clusterfuck and I have yet to arrive at a satisfactory solution myself despite wasting inordinate amounts of time on it. IMO you either go with a network share or you make due with the "least bad" option of syncthing. Personally I've more or less settled on sshfs at this point not because it's particularly good but because it works well enough and doesn't add any additional complexity.

Personally I use btrfs snapshots on all my devices, those get streamed across the network to a NAS, and the contents of the NAS are periodically (every few months) stuffed into borgbackup on redundant offline devices. Aside from sync the other problem you'll run into if you're a data hoarder is how to split backups across multiple drives once you exceed a few TB. Because external drives only get so large but the NAS will inevitably keep ballooning.

nolist_policy27 minutes ago
> Sync, rotating snapshots, and deduplicated backups need to be kept entirely separate if you want any hope of maintaining your sanity.

Not if you use git-annex.

fc417fc8025 minutes ago
Huh, I'd heard the name before but I hadn't realized how capable it was. Unfortunately when it comes to a data hoarder such as myself:

https://git-annex.branchable.com/scalability/

> Scaling to hundreds of thousands of files is not a problem, scaling beyond that and git will start to get slow.

So that's probably insufficient for me by at least a couple orders of magnitude.

smarmellingabout 2 hours ago
I agree I think one of the main things I learned from all this was that I should probably buy / set up a real NAS. I’ll look into zfs pool thanks for the comment!
XorNot15 minutes ago
Fair warning with ZFS: do not turn on deduplication at the moment.

There is a straight up data loss bug in 2.4.3 (zeroed out files, totally silent).

https://github.com/openzfs/zfs/issues/18366

This caused all sorts of grief at day job where dedupe was useful for a big cache. Conversely I've run ZFS at home for like 15 years at this point without trouble. But this one is an absolute nightmare.

xbarabout 2 hours ago
I liked the post because it tells a true story about one of the remaining problems that are hard to solve well without a 3rd party.
drdexebtjlabout 3 hours ago
It sounds like most of your frustration can be eliminated by actually using your NAS as the ground-truth for all data, using something like SMB/NFS instead of SyncThing.

Then you only need to backup the NAS.

smarmellingabout 2 hours ago
Oh interesting I hadn’t considered this. I guess the only trouble would be if I am out with my laptop and I have no internet connection but this seems like a good tradeoff for simplicity
zenopraxabout 1 hour ago
Beware of interactions with git and syncthing. It's fine for straightforward repos where all you do is commit but as soon as you start doing more complicated branching and re-basing you will start to generate lots of `sync-conflict` files. I haven't really found a reliable way around this so I've decided to just manually rsync from my desktop onto my laptop when I want to work remotely (or more recently, SSH into my desktop directly instead and work off that).
XorNot10 minutes ago
I have a ~/git folder which I keep bare git repos in and push to.

That gets synced and it's been trouble free so far.

Hamukoabout 2 hours ago
Apple's Time Machine still backs up your Mac even when you don't have access to the backup target (USB isn't connected, network isn't available). It just stores the backup information on your local storage and then transfers it over to the actual backup target when it's back online. Don't know if there's similar solutions for non-macOS systems though.

https://support.apple.com/en-us/102154

eviks27 minutes ago
> It contains at the home directory the folder Sync which is what gets synced across all devices and what needs to be maintained.

That's a core Dropbox-level mistake of putting the backup cart before the main use horse - your files should be sorted according to their primary, not backup use

> Syncthing works very well, its only constraint is that it does need the devices to be often on if you want consistent syncing.

So it's working very poorly, this is a very inconvenient constraint

> phone is a whole other beast. It does not have enough storage to

Indeed

Overall, that fits the title perfectly, and is a bad way to setup your backups. Special needs need special apps.

exe341 minute ago
What solution do you use that syncs/backs up while the device is turned off? IME stuff?
yread35 minutes ago
Just get a tape drive. Then you will find out how nice and simple disks are
aidenn0about 2 hours ago
Why wouldn't you use NTFS for backing up a windows system?
tehbeardabout 1 hour ago
It's a pain in the ass on new systems if it copied restrictive permissions to reset/gain access.

Ntfs equivalent of Chmod/chown is a "go have a long lunch" type of operation.