Bacula-users

Re: [Bacula-users] backup encryption

2011-01-30 21:03:49
Subject: Re: [Bacula-users] backup encryption
From: "James Harper" <james.harper AT bendigoit.com DOT au>
To: "Marc Dojka" <mdojka AT gmail DOT com>, "Dan Langille" <dan AT langille DOT org>
Date: Mon, 31 Jan 2011 13:01:32 +1100
> 
> For the backups:  The media is stored at an offsite location.  When
the media
> leaves my control, all data must be encrypted.  This is for policy
reasons,
> insurance reasons, and ensures confidentiality of customer information
as well
> as HR records.

We just had a situation recently (Backup Exec but the point still
stands) where a tape drive failed so we bought a couple of 2TB USB disks
to use for a few days while the drive was diagnosed and replaced.

The first USB backup completed after about 36 hours and then the drive
failed completely (won't even spin up) 2 hours later. It's a 2TB drive
(1TB would have worked with about 2GB to spare!) and cost about AUD$235.

So now we have a $235 drive that can't be used anymore and can't be
returned under warranty because it is full of customers data, and can't
be erased because it's dead. Tried all the standard revival techniques
but it's a sealed unit so we can't open it up to test if it's a drive or
controller issue. If we had used encryption then it would have been fine
to return.

> For the keys:  So even if both the backups and the keys are
compromised, they
> are unusable without the private key password.
> 

Just make sure you keep a copy of the keys and the password offsite :)
 
James


------------------------------------------------------------------------------
Special Offer-- Download ArcSight Logger for FREE (a $49 USD value)!
Finally, a world-class log management solution at an even better price-free!
Download using promo code Free_Logger_4_Dev2Dev. Offer expires 
February 28th, so secure your free ArcSight Logger TODAY! 
http://p.sf.net/sfu/arcsight-sfd2d
_______________________________________________
Bacula-users mailing list
Bacula-users AT lists.sourceforge DOT net
https://lists.sourceforge.net/lists/listinfo/bacula-users