Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No backup? Seriously? Wow.

What do people like for backups these days? Crashplan seems pretty damn good to me.



CrashPlan has swooped in and knocked every cloud backup system I previously used to use out of contention.

They've made an awesome product and they provide it at an awesome price.

Previously, I was a user and big proponent of Jungle Disk, but that product has become all but completely abandoned since being gobbled up by Rackspace. (I love how their solution to comments about going radio silent and not updating their blog in over a year was to just take the blog down and put up a "The Jungle Disk blog is currently unavailable" message, as if the blog were just temporarily offline. One of their last blog posts was a "Future of JungleDisk" post, outlining tons of features that, 16 months later, were nowhere to be seen).

I had been recommending Carbonite to friends and family for an easy-for-normal-people backup solution, but their performance falls short of CrashPlan, and their heinous near-silent default exclusion of video files from backups would have led to serious tears if we had ever actually needed to restore from backup. (Automatic backing up of video files is reserved as a feature for the new $150/yr HomePremier plan - which at least now makes this fact somewhat visible. Previously, there was damn little to indicate that this exclusion was happening). That made Carbonite something much less than the "set it and forget it" backup for my non-technical friends and family that it was supposed to be.

CrashPlan is nice and friendly, has no hidden "gotchas" that I have found yet, and has a great PRO service as well. The client GUI can even be made to connect to the daemon on a headless server through an SSH tunnel, just with a simple change in port number in the config and forwarding the remote port through the tunnel.


I absolutely love CrashPlan, but it is only friendly if you never need to change the backup selection. It gets tough when you want to deselect just the right folders to avoid spamming your backup destinations with useless crap like Xcode docsets and Safari caches.


...Wait, you mean, an online backup service that sends emails (and password reset requests) to an email account that can be compromised?

Hm.


Crashplan does not require you to use its cloud storage, FWIW.

And after you've logged in to Crashplan, it's not clear to me that you can do a whole lot of damage via the website; the password used to encrypt your data is specified on the client side, and there is no reset mechanism for it. I mean, they could update the credit card settings, or modify the configuration options like excluded directories or send rates, but not a whole lot else.


But, but, it must be in the CLOUD, don't you know?


You can configure CrashPlan to encrypt your archives such that you must have your password to decrypt them. There's a big warning that if you lose your password you're screwed.

Also, you can just specify your own encryption key. Everything is encrypted locally.


Question: could an attacked delete my CrashPlan backup via the website?

It seems like they should be holding on to files for 30 days period or something. Does anyone know?


Doesn't look like they hold on to the data if you remove a computer from your CrashPlan account: http://support.crashplan.com/doku.php/how_to/remove_a_comput...

(I do like CrashPlan, but this seems to be common practice with data storage services.)

Removing the computers associated with a CrashPlan account and then cancelling the account looks like it'll cause a pretty big headache.


I haven't tried Crashplan, but I recommend either Backblaze or SpiderOak. I used SpiderOak in the past when I had both a Windows and a Linux PC I needed to keep backed up, but now that I have one Windows PC I use Backblaze.

Backblaze really shines if you have a single Windows or OS X PC with a lot of data. For $50/year, it will allow you to backup unlimited data for a single computer. As far as I know there is no student discount.

SpiderOak really shines if you have multiple Windows, OS X or Linux PCs with a small amount of data between them. For $100/year, it will allow you to store up to 100GB of data between as many computers as you want to back up. If you're a student, it will only cost $50/year.


Crashplan has a home plan that lets you back up unlimited data for all your machines. It works on Windows, OS X, Linux and Solaris, which is great for me; I back up all my machines to both the cloud and my Nexenta/Solaris NAS, as well as backing up the NAS. In fact, if you know other people who have lots of storage, you don't have to pay for Crashplan at all; you can back up to them, with encrypted data.


Custom backups using Duplicity+GPG to multiple clouds. Wuala[1] if you want something working out of the box. I have 18.5 GB of free storage just from coupons found with little Googling[2].

[1] https://www.wuala.com/

[2] http://static.deno.pl/pub/wuala-storage.png


Looked into Wuala. I like this part:

"Wuala is completely private and secure. When you store a file in Wuala, the file [..]gets encrypted before it leaves your computer. [..]Your own password is very important here: it never leaves your computer, so we do not know it. Hence, not even we can access your data."

- https://www.wuala.com/en/support/faq

But it seems pointless in light of:

"Do you plan to open the source code?

Currently not. Opening the source code of Wuala would consume quite some time and effort, and commitment to maintain it. If you are a software engineer and would like to see how Wuala works, feel free to apply for a job at Wuala."

- https://www.wuala.com/en/support/faq/c/21

It would be trivially easy for them to hide a backdoor and/or leak data in their closed-source code. So at the end of the day, the message is "Trust us." So what purpose does the client-side encryption serve? Empty marketing. At best, it makes it _slightly_ harder for them to read your files.

Tarsnap (www.tarsnap.com), which does have client source code available, doesn't suffer from this problem. Unfortunately it's a fair bit more expensive.


I'm Luzius Meisser, cofounder of Wuala. Yes, some trust in Wuala is still required, namely trusting us that we won't put a backdoor into the client. Much more trust is required in services without client-side encryption. Adding a backdoor would ruin our reputation once someone found out, while companies like Dropbox won't suffer much when they hand over data to a government agency as it is known that they can and will do it. Also, bugs like accidentally disabling the password verification can be ruled by design with client-side encryption.

Also, please note that laws are often constructed such that companies can be forced to hand over data they possess, however not to collect data they do not possess yet. E.g. there are many laws in many jurisdictions that could be used to force Google to hand over data you have stored in Google Drive, but the same laws cannot be used to force us to add a backdoor to Wuala. So legally, it is much much easier to obtain data stored in Google Drive than to obtain data stored in Wuala (or another service that uses client-side encryption). Noone has ever asked us to add a backdoor to Wuala and we would fight against it if someone did.

I agree that it would be nicer to open the source code so our security would be independently verifiable, but claiming that what we do is "empty marketing" is clearly wrong.


Thanks for the reply. I see what you mean and agree there is some difference. Let me put it this way: I would feel confident my Wuala backup is secure from my boss or ex-girlfriend, but not from a hostile government. If I were an activist or otherwise doing something very controversial, I wouldn't trust it. And honestly, that's the same way I feel about Dropbox. It's not the most secure thing around, but as long as I'm just another J. Random Hacker, who cares? So to me there isn't a distinction.

For why not to trust a closed-source system's claims of security, see Skype. If I remember correctly what I have read, they boasted about using "end-to-end encryption", strongly implying that your Skype calls could not be wiretapped. The catch? The encryption keys were stored on the server! And there was a story where someone (a drug smuggler, I think) was busted seemingly as a result of intercepted Skype calls. The misleading claims of security didn't ruin Skype's reputation - people still use it.

I'm glad you replied to my comment as it shows you're at least thinking about these things. I hope you will consider opening your source code in the future. At that point Wuala might be of interest to me.


EU laws give you some protection. Still, this is why I don’t use it for backups myself. Their technology is quite good though, it uses similar snapshot based model that Tarsnap does and has very small footprint, considering. Hopefully they will be able opensource it at some point.


Wuala is great but not recommendable for backups if you care for Mac metadata and an app running silently in the background. I have no idea why Wuala has not implemented these features after all the years. Crashplan is Java-based too and has both features.


I recommend BackBlaze to my friends for the simple reason that it's saved my bacon once, after a laptop theft. I'd have lost years of data otherwise. It also helped me give the police information that resulted in my laptop's physical recovery.

Full story, from last fall: http://prog.livejournal.com/983354.html


I use a mixture of Crashplan (but only locally between machines because our DSL connection is waaay too slow) and DropBox.

I'd be curious to hear more about other people's solutions.


Been using Crashplan for couple of years now. For a couple days pay you can backup so much.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: