Bacula-users

Re: [Bacula-users] Strange issue with backup size

2013-04-08 07:29:05
Subject: Re: [Bacula-users] Strange issue with backup size
From: Radosław Korzeniewski <radoslaw AT korzeniewski DOT net>
To: Alberto Caporro <a.caporro AT consulthink DOT it>
Date: Mon, 8 Apr 2013 13:25:56 +0200
Hello,

2013/4/8 Alberto Caporro <a.caporro AT consulthink DOT it>
I was on the point of making the same exact remark.

There's for sure a minor information leak (knowing the actual size of a sparse file),

It is not about a file size. All file metadata are unencrypted and simply available on the Bacula volume, so you can get it directly from volume or catalog.
 
but I fail to understand how an attacker could possibly take advantage of that, in the (IMHO) highly unlikely event that she is able to steal your backup tapes and make sense of what they contain.

It is about "Known plaintext attack".

I could be wrong about it and Bacula encryption could not be susceptible to this kind of attacks.

best regards
--
Radosław Korzeniewski
radoslaw AT korzeniewski DOT net
------------------------------------------------------------------------------
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
_______________________________________________
Bacula-users mailing list
Bacula-users AT lists.sourceforge DOT net
https://lists.sourceforge.net/lists/listinfo/bacula-users