Re: Tar backups creating secure tape image?

From: Chris Mattern (syscjm_at_gwu.edu)
Date: 08/26/03


Date: Tue, 26 Aug 2003 15:47:45 -0400

Marc David Ronell wrote:

Please don't email *and* post to the newsgroup; I had no idea that
this reply went to the newsgroup. Just reply to the newsgroup
unless you have a need to talk to me privately. Thank you.

>>>"Chris" == Chris Mattern <syscjm@gwu.edu> writes:
>>
>
> > Marc David Ronell wrote:
> >> Is there a good method to use tar to create secure tape backups?
> >> The goal is to encrypt each file individually and then put the
> >> encrypted file into the archive. Encrypting the archive would
> >> seem to yield a fragile backup and is not desired.
> >>
> > Encrypting backups strikes me as a rather poor idea. The last
> > thing you need is to be locked out of your backups when you need
> > them. Tapes are offline when not being used anyways. Maintain
> > proper physical security of your tape vault and that should take
> > care of your security requirements.
>
> Most places I have been in do not, unfortunately , have a tape vault.

Really? I've never worked in a data center that didn't have one.

> Also, doesn't it seem silly to have logins and password protection on
> normal machine access, but not on backups? If one cannot break into a
> machine, it is trivial to borrow a recent backup tape.

Trivial? Once again, every place I've ever worked, only ops and the
admins had physical access to the backup tapes. Frankly, if any user
can walk in and grab your backup tapes, you have no backups that you
can count on. Even if they're encrypted, your user can still just
wipe the tape (or steal it).

Physical security of your machines and media is step one in securing
your servers. Without that, you might as well not bother, because
you don't have any security.

                       Chris Mattern



Relevant Pages

  • Re: audit user activity
    ... you can set filter to view the Security log for a particular user. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... Right-click Small Business Server Auditing Policy and click Edit. ...
    (microsoft.public.windows.server.sbs)
  • Re: A new Beta test from Panda
    ... | Paypay/ebay) I have switched ISP, ... connection to computer security and vulnerability, well, I judge on ... every Usenet newsgroup message posted in the last 25 years, ... Internet gambling account and immediately contacted him. ...
    (microsoft.public.security.virus)
  • Re: A new Beta test from Panda
    ... It's been refreshing to 'talk' to you here, Phil. ... connection to computer security and vulnerability, well, I judge on ... every Usenet newsgroup message posted in the last 25 years, ... Internet gambling account and immediately contacted him. ...
    (microsoft.public.security.virus)
  • Re: Open source in the national interest
    ... newsgroups where people can discuss how to IMPROVE security of Microsoft ... The name of this newsgroup is microsoft.public.security *not* ... You are saying this is not the right ...
    (microsoft.public.security)
  • Re: Hijacking of seeks
    ... Smiles are meant to be shared, ... > next Windows restart. ... with the Windows XP Security Center and it is very annoying. ... Replies posted only to the newsgroup for the benefit or other readers. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)

Quantcast