Gentoo Archives: gentoo-security

From: David Talkington <dtalk@××××××××××.org>
To: cummings@××××××××.net
Cc: Tobias Weisserth <tobias@×××××××××.de>, Paul de Vrieze <pauldv@g.o>, gentoo-security@l.g.o
Subject: [gentoo-security] Re: System knockout :-(
Date: Sat, 03 Apr 2004 18:49:25
Message-Id: Pine.LNX.4.58.0404031038420.21304@atlantis.dj
In Reply to: Re: [gentoo-security] System knockout :-( by cummings@stingray.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 cummings@××××××××.net wrote:
5
6 >> Backups are not the problem... Reinstalling a perfectly well tuned
7 >> Gentoo system gives me the shivers... I'm seriously thinking of using
8 >> mirrored raid partitions next time.
9 >
10 >I considered a Raid 1 solution, but it's slow and has one major drawback.
11 >What happens if you get hacked because a security problem is slow to get
12 >patched? With raid 1 both drives get hacked, but if you manually mirror
13 >the second drive on changes if you get hacked you would be able to swap
14 >them, update the problem, then mirror the fixed system to the previously
15 >hacked version, saving you the time of recompiling and tuning the system.
16
17 Repeat after me as you write on the chalkboard 100 times (*):
18
19 RAID is not a backup solution.
20
21 It is uptime protection against a very specific set of possible
22 hardware-related failures. Disk redundancy does nothing to protect you
23 from deleted files, breakins, emerges gone awry, careless use of root
24 privilege, scripting bugs, corrupted filesystems, improper shutdowns, ad
25 nauseum. Make backups. If you have data that you truly care about,
26 make offsite backups.
27
28 Good luck ... -d
29
30 (*) I wish I'd known about for() loops in 3rd grade. :)
31
32 - --
33 David Talkington
34
35 PGP key: http://www.prairienet.org/~dtalk/004B8F8B.asc
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.2.4 (GNU/Linux)
38
39 iD8DBQFAbwcd5FKhdwBLj4sRApO3AJ0efnH7wBlbdr8HvCyg7N8nzwxJJgCgo2KF
40 3QThKkRpg5Op8Saki5hj90c=
41 =mBfT
42 -----END PGP SIGNATURE-----
43
44 --
45 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Re: System knockout :-( Barry Schwartz <trashman@×××××××××.com>
[gentoo-security] Re: System knockout :-( Tobias Weisserth <tobias@×××××××××.de>