Why is that the case and wouldn’t that make the encryption very weak? Simultaneous updates happen quite often.
Would restic have the same problem?
——————-
Update: The issue happens because Borg uses AES in the CTR mode (not AES GCM) and two clients could provide the same nonce. The server could then recover the plaintext from two cipher texts. This is the famous nonce reuse problem.
So Borg developers are not using established primitives for this use case. Also, I am not comfortable with the OpenSSL even though it’s got better since 2015. The libssl code base is a mess and buggy. On the other hand using the low level libcrypto library would expose developers to the crypto primitives with possibilities for errors for people not expert in cryptography.
Borg should consider ChaCha-Poly135 as in rclone (or at least AES-GCM).
[0]https://borgbackup.readthedocs.io/en/stable/internals/securi...