1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
cummings@××××××××.net wrote: |
5 |
|
6 |
>> Backups are not the problem... Reinstalling a perfectly well tuned |
7 |
>> Gentoo system gives me the shivers... I'm seriously thinking of using |
8 |
>> mirrored raid partitions next time. |
9 |
> |
10 |
>I considered a Raid 1 solution, but it's slow and has one major drawback. |
11 |
>What happens if you get hacked because a security problem is slow to get |
12 |
>patched? With raid 1 both drives get hacked, but if you manually mirror |
13 |
>the second drive on changes if you get hacked you would be able to swap |
14 |
>them, update the problem, then mirror the fixed system to the previously |
15 |
>hacked version, saving you the time of recompiling and tuning the system. |
16 |
|
17 |
Repeat after me as you write on the chalkboard 100 times (*): |
18 |
|
19 |
RAID is not a backup solution. |
20 |
|
21 |
It is uptime protection against a very specific set of possible |
22 |
hardware-related failures. Disk redundancy does nothing to protect you |
23 |
from deleted files, breakins, emerges gone awry, careless use of root |
24 |
privilege, scripting bugs, corrupted filesystems, improper shutdowns, ad |
25 |
nauseum. Make backups. If you have data that you truly care about, |
26 |
make offsite backups. |
27 |
|
28 |
Good luck ... -d |
29 |
|
30 |
(*) I wish I'd known about for() loops in 3rd grade. :) |
31 |
|
32 |
- -- |
33 |
David Talkington |
34 |
|
35 |
PGP key: http://www.prairienet.org/~dtalk/004B8F8B.asc |
36 |
-----BEGIN PGP SIGNATURE----- |
37 |
Version: GnuPG v1.2.4 (GNU/Linux) |
38 |
|
39 |
iD8DBQFAbwcd5FKhdwBLj4sRApO3AJ0efnH7wBlbdr8HvCyg7N8nzwxJJgCgo2KF |
40 |
3QThKkRpg5Op8Saki5hj90c= |
41 |
=mBfT |
42 |
-----END PGP SIGNATURE----- |
43 |
|
44 |
-- |
45 |
gentoo-security@g.o mailing list |