Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And that is why I have the "if you don't have backup, I won't bother to help you with your lost files" policy when friend or family come crying. I make only one exception from this rule.

Cryptolocker is not the problem. The lack of reliable backup is.

15 years into the internet age, and 5 into the cloud you have no excuse.



What you should have mentioned is how many years since the start of the personal computer.

People simply cannot be computer-illiterate in the modern world without eventually being screwed. Nearly every computer ignorant person I know has a virus/spyware/adware ridden PC sitting at home while they're just waiting to find a "computer guy" who can fix it.


I would genuinely rather lose all my critical data to cryptolocker than put it in the cloud. Given a choice between my data being accessible by no-one or everyone, I will pick no-one every time.

Data in the cloud /is/ available to everyone that matters.

I'd also like to remind you that it can be impractical to back up some forms of data, especially in the cloud. High definition video (weddings, funerals, holidays) is impractically large.

The problem /is/ Cryptolocker. Anyone with an ounce of practicality will take mitigating steps against it, I have no sympathy for anyone who ignores the risk, but the solution is not massive scale global data duplication, that is treating the symptoms. The solution is to dissuade criminals from this path.

Widescale international cooperation in finding these people would be a start.


You don't need to backup to the cloud, have people forgotten about physical hard drives?


I do have a physical hard disk for my backups but I also backup some critical data "on the cloud" (actually, some servers of mine). There is always a chance that the pc and the disk are stolen by a burglar or my house catches fire. Then there is the matter of making the encryption and access keys survive any of those events.


Yep, a good mitigation plan is a 2tb time capsule. All my precious cat photos are backed up on the regular, encrypted and within reach.


As long as you remember to keep that drive unplugged - otherwise it'll get cryptolocked with everything else.


Here is a good interview question:

Design a simple system that uses amazon as backend to store encrypted data and the keys never leave your control.

There were 4TB drives at 100-sh bucks for big things.

The problem is not Cryptolocker because there will ALWAYS be malware that targets the data itself. And some people will do it just for fun.


I think Duplicity (http://duplicity.nongnu.org) is what you're looking for. For Ubuntu I know there's a nice GUI that anyone who can use a computer can set up. For other platforms I think cli is the only way, but someone could just write a QT/Cocoa wrapper around it.


Duply (http://duply.net/) is a wrapper around Duplicity, and there's a GUI front-end called Deja Dup too: http://live.gnome.org/DejaDup/Screenshots

I use Duply to schedule incremental backups of my server logs to S3 (write only) and then have S3 expire them after 60 days. Works great.


Or, don't be dumb and use tarsnap. encypting backups is not an impossible (or even hard) problem.


Indeed, having a recent valid backup turns the cryptolocker variety of virus quite ineffective, you only lose some time to restore vs files you can't replace.

But how is this related to the internet or the cloud in any way? Putting backups into the cloud is a terrible idea and transferring large data collection over a residential Internet connection makes little sense. Backups for home users became a possibility with the advent of cheap storage, first burners and cheap blank discs and now with large hard drives and flash media.

But the issue at hands here is that with the democratization of the personal computer most users lacks the skills to make their own backups and even among technical people it's not until we got bitten by data loss that we start to take backups seriously.


I'm sorry, but I do exactly what you say is impossible.

  > Putting backups into the cloud is a terrible idea
  > and transferring large data collection over a
  > residential Internet connection makes little sense.
I work with video, music and large images. So my home backup is 3.6 TB. I now use CrashPlan: a cloud backup, who have no problem with the capacity. It took ~ 6 months to store everything, but now it just sends the deltas quietly behind the scenes.

I lost a 1TB drive the other day, and the restore worked well after a bit of jiggerypokery.

Previously I used an LTO2 tape system involving Bacula, a VMWare linux instance and a lot of changing tapes. Cloud backup is so much better


> Backups for home users became a possibility with the advent of cheap storage, first burners and cheap blank discs and now with large hard drives and flash media.

Now your home users need to start regular media rotation with scheduled integrity checks with a full copy stored off-site in a geographically diverse location. Are you starting to reconsider your assertion that “putting backups into the cloud is a terrible idea”?


I did not say put it in the cloud. Although it is totally possible to create backup solution that is undecryptable by the cloud hosting provider.


"15 years into the internet age, and 5 into the cloud you have no excuse." Yes, you did.


And after the backup don't forget to detach the external storage and logout from the cloud storage otherwise they could just encrypt those too.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: