Gentoo Archives: gentoo-user

From: Michael Orlitzky <michael@××××××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] {OT} Are "push" backups flawed?
Date: Sun, 13 Nov 2011 20:44:48
Message-Id: 4EC02BED.4030402@orlitzky.com
In Reply to: Re: [gentoo-user] {OT} Are "push" backups flawed? by Grant
1 On 11/13/11 13:03, Grant wrote:
2 >>>> And if I pull, none of my backed-up systems are secure because anyone
3 >>>> who breaks into the backup server has root read privileges on every
4 >>>> backed-up system and will thereby "gain full root privileges quickly."
5 >>>
6 >>> IMO that depends on whether you also backup the authentication-related
7 >>> files or not. Exclude them from backup, ensure different root passwords
8 >>> for all boxes, and now you can limit the infiltration.
9 >>
10 >> If you're pulling to the backup server, that backup server has to be
11 >> able to log in to and read all files on the other servers. Including
12 >> e.g. your swap partition and device files.
13 >
14 > What if I have each system save a copy of everything to be backed up
15 > from its own filesystem in a separate directory and change the
16 > ownership of everything in that directory so it can be read by an
17 > unprivileged backup user?
18
19 You've just reinvented the push backup =)
20
21 If separate-directory is on the same server, an attacker can log in and
22 overwrite all of your files with zeros. Those zeros will be pulled to
23 the backup server, destroying your backups.
24
25 If separate-directory is on the backup server...

Replies

Subject Author
Re: [gentoo-user] {OT} Are "push" backups flawed? Grant <emailgrant@×××××.com>