Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] {OT} Are "push" backups flawed?
Date: Sun, 13 Nov 2011 18:06:44
Message-Id: CAN0CFw1Xv-1wJTx0RjehDKm0vyAmQvXUFJiM7WfmNw2edYzK-g@mail.gmail.com
In Reply to: Re: [gentoo-user] {OT} Are "push" backups flawed? by Michael Orlitzky
1 >>> And if I pull, none of my backed-up systems are secure because anyone
2 >>> who breaks into the backup server has root read privileges on every
3 >>> backed-up system and will thereby "gain full root privileges quickly."
4 >>
5 >> IMO that depends on whether you also backup the authentication-related
6 >> files or not. Exclude them from backup, ensure different root passwords
7 >> for all boxes, and now you can limit the infiltration.
8 >
9 > If you're pulling to the backup server, that backup server has to be
10 > able to log in to and read all files on the other servers. Including
11 > e.g. your swap partition and device files.
12
13 What if I have each system save a copy of everything to be backed up
14 from its own filesystem in a separate directory and change the
15 ownership of everything in that directory so it can be read by an
16 unprivileged backup user? Then I could have the backup server pull
17 that copy from each system without giving it root access to each
18 system. Can I somehow have the correct ownerships for the backup
19 saved in a separate file for use during a restore?
20
21 - Grant

Replies

Subject Author
Re: [gentoo-user] {OT} Are "push" backups flawed? Florian Philipp <lists@×××××××××××.net>
Re: [gentoo-user] {OT} Are "push" backups flawed? Michael Orlitzky <michael@××××××××.com>
Re: [gentoo-user] {OT} Are "push" backups flawed? Michael Orlitzky <michael@××××××××.com>