1 |
On 11/11/2011 09:22 PM, Grant wrote: |
2 |
> |
3 |
> So if I push, I don't really have backups because anyone who breaks |
4 |
> into the backed-up system can delete all of its backups like this: |
5 |
> |
6 |
> rdiff-backup --remove-older-than 1s backup@12.34.56.78::/path/to/backup |
7 |
> |
8 |
> And if I pull, none of my backed-up systems are secure because anyone |
9 |
> who breaks into the backup server has root read privileges on every |
10 |
> backed-up system and will thereby "gain full root privileges quickly." |
11 |
> |
12 |
|
13 |
It's a false dichotomy[1], but sums up the trade-off between those two |
14 |
options well enough. |
15 |
|
16 |
The last "hacker" who tried to delete everything on my system was a |
17 |
5.25in floppy. So, I'm biased towards the other case. |
18 |
|
19 |
|
20 |
[1] Third option: choose push or pull, and ALSO make off-site read-only |
21 |
backups of the backup server every once in a while. |