Backblaze Hard Drive Stats Q3 2020
backblaze.com
backblaze.com
I also wish that Backblaze would focus on their product security[0] as much as they focus on promoting this quarterly hard drive report.
[0] https://twitter.com/zetafleet/status/1304664097989054464
In 2015 Facebook published* its study of flash memory failures at scale. By all means it's a terrific paper (of course I'm biased) but I think it was irrelevant not only for consumers but pretty much 99% of the flash users in the industry.
[*] http://users.ece.cmu.edu/~omutlu/pub/flash-memory-failures-i...
Were there any follow-ups from Backblaze?
One thing you can independently verify is that the backdoor string is still in their client. The installer starts transmitting data during the installation process, so I would not recommend installing it outside of a VM—just look at the files directly. The macOS installer has it in `Backblaze Installer.app/Contents/Resources/instfiles.zip/bztransmit`. The Windows installer is a self-extracting ZIP file, so just use unzip and look in `bztransmit.exe` and `bztransmit64.exe`.
$ strings bztransmit |grep BACKDOOR
DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file exists:
ERROR DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file could not be read:
ERROR DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file existed but less than 10 chars or could not be read:
ERROR DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file did not contain bz_cvt:
ERROR DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file contained bz_cvt but wrong num digits:
ERROR DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file did not contain bz_upload_url:
ERROR DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file contained bz_upload_url but did not start with http:
DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml file exists and is valid and bz_cvt=
DoHttpPostSyncHostInfo - BACKDOOR_prefer.xml SUCCESSFULLY_swapped_in new_bz_cvt=
What does the corresponding code do? I genuinely don’t know. My goal was to find backup software, not to do a security analysis. An easy-to-exploit root code execution vulnerability was enough for me to uninstall the software, submit a report as a professional courtesy, and go do something else.Clearly it’s dumb to put the word BACKDOOR in your code if your goal is to plant a secret backdoor, but it’s also pretty dumb to use world-writable directories, disable host certificate verification, use magic hard-coded strings to “sign” updates, and implement data encryption in a way which requires the ‘private’ password to be sent to the server, so who knows. As I said in the tweet, even if it turns out to be innocuous, the optics are terrible and show a serious lack of good judgement on their part, especially given how much they claim to be security experts who care about their reputation[0].
> Were there any follow-ups from Backblaze?
No. The only “follow-up”, as it were, was to cancel their HackerOne public bug bounty programme. (Though this was a month ago, their web site still tells people to “visit our public bug bounty program managed through Hacker One”[2].) They have not communicated with me at all except for one tweet about that change[1]. I have seen no public statement from them acknowledging that this happened, or that they made mistakes, or that they have steps they plan to take to improve their internal software development practices.
[0] “We stand by our reputation as trustworthy, careful programmers who have worked in the security field for over a decade. […] we have LOTS of interest in keeping our reputations rock solid and utterly clean.” https://help.backblaze.com/hc/en-us/articles/217664798-Secur...
[1] https://twitter.com/backblaze/status/1308157606368882688
Did you achieve your goal (i.e., did you find backup software you trust)?
For cloud backups, I’m still looking. My personal criteria are security (of course), good data integrity management, continuous backup, upload speed, and low resource utilisation. I was hoping to find something which was also simple enough that I could also tell non-technical friends and family to just use <whatever>. What I found was:
Backblaze… well, you know.
Carbonite uses Java and is slow.
SpiderOak uses Python and is slow.
Duplicacy uses Go along with a local web interface for the consumer version. It currently consumes way too much memory during backups[0].
IDrive I never tried installing; I was put off by how it appears to uses a fleet management model where configuration relies on visiting their web site and having stuff get pushed down to the client.
Acronis True Backup somehow manages to be 700 megabytes on disk. I thought they must be using CEF, but no, it seems to just contain a truly colossal amount of code along with a 100 megabyte help file.
At some point I stumbled across Arq, which looked like it could be a winner: they’ve published a couple CVEs on their site like a good company should; they have a monthly sub or you can just buy the software outright and use your own cheap cloud storage like S3 Glacier; they even publish the format of their backup files[1]. But then they went and released Arq 6 using CEF for the UI. It looks like they listened to feedback from users and will be going back to a native UI for Arq 7, and so I plan to take a serious look at this once it is released.
[0] https://forum.duplicacy.com/t/memory-usage/623/
[1] https://www.arqbackup.com/docs/arqcloudbackup/English.lproj/...
There was always a nagging voice in the back of my head - "their backup encryption can't possibly be good" - but I wanted to believe it since their deal is so good, in terms of storage per dollar, and it's hard for me to afford otherwise right now. I did a bit of digging not too far back and their help pages go into a small amount of detail but ultimately just say "trust us". I trusted them to throw away my encryption password after a session, which is terrible, of course. After reading all of your work, I cannot even countenance trusting them anymore.
Ironically the first thing that comes to my mind for offsite backup is Backblaze B2... if you do all the encryption before it leaves your machine, then it doesn't matter what they do, and their storage is cheap. Rclone or similar means that their client software need not be trusted. It's up to whether you tolerate their business practices.
You mentioned in another comment that you are still looking for cloud backup software which ticks all the boxes - why did you not go with Rclone? On the surface it looks great but I haven't tried it yet.
Business practices aside, the problem I personally have is: seeing how they are dishonest about their client security, how much can I trust that they’re honest about their durability or server-side security? Encrypting blocks myself ensures confidentiality, but how do I trust that data aren’t being silently lost or corrupted at rest? They hand-wave about how 11-9s durability doesn’t matter[0] in the same way they hand-wave about how zero-knowledge data privacy doesn’t matter, while simultaneously mentioning that they have, in fact, experienced unrecoverable data corruption in the past[1].
> why did you not go with Rclone?
There’s a long tail of roll-your-own cloud backup tools like this that I didn’t really evaluate: Rclone, BorgBackup, restic, Duplicity, Tarsnap, etc. I just ran out of energy and really wanted to avoid something that required a bespoke setup. These tools might work for me, but they wouldn’t be something I could recommend to a non-technical user, and I’m not sure if any of them have daemons for performing continuous backup, so I’d have to figure out a separate solution for that which might be buggy.
In any case, it looks like rclone may have some of the same problems as Duplicacy and restic with using too much memory[2][3].
[0] https://www.backblaze.com/blog/cloud-storage-durability/
[1] “If a cosmic ray has thrown a bit, we ask your computer to retransmit that particular file. This rarely, rarely happens, but in our datacenter of quadrillions of trillions of files in 350 petabytes of customer data. It DOES occur once in a while.” https://help.backblaze.com/hc/en-us/articles/217664798-Secur...
[2] https://rclone.org/faq/#rclone-is-using-too-much-memory-or-a...
I went through three rounds of 4x 12TB Seagate Exos X16 drives last month through different safe vendors. 100% of the drives arrived DOA (tested in a bunch of different machines). Switched to 16TB Toshiba MG08s and smooth sailing since.
I know the dead ones tend to cluster because of their manufacturing, but I ended up having serious questions about their QC process. Talking to some of my peers, Seagate seems to be a bit of an embarrassment for a long time.
With failure rates of in-service drives mostly being similar, I start to become much more interested in data about a brand/product's quality control process.
Not nearly as clean (and representative) a datsset as y'all would have.
https://www.instructables.com/How-to-Fix-the-33V-Pin-Issue-i...
Clearly, given these numbers, Backblaze thinks the same way.
Earlier this year I had a Seagate fail within months of purchase, putting my NAS into degraded performance mode. So I quickly ordered a replacement drive (a WD Red) and started the RMA process for the Seagate. At some point during this process I removed and reinserted the Seagate, and... its been fine since. So now I have a WD cold spare in my closet for whichever drive fails next.
If you have a pool of 8tb drives and want to replace with a 7.9tb drive, you're out of luck.
Same here - created on each drive a partition slightly smaller than the HDD's capacity (using ZFS raidz1).
(but of course this may not be economical in every situation)
These types of things aren't free, but they're inexpensive enough to be worth it, IMO.
Wish Backblaze had SSD stats.
My question is, what is happening to HGST the brand?
Western Digital were supposed to phase out the brand, and only keeping the Gold or UltraStar branding. That was may be 2 years ago.
Except HSGT is still everywhere. And I know people demand HGST. I think partly due to Backblaze's numbers. Even the Western Digital UltraStar still has HGST in labels, stickers or description somewhere. Retailers simply call them HGST WD most likely because that is what customers want or are looking for.
It seems Western Digital did at one point try to move their marketing material to focus on UltraStar, but my suspicious is that people still want HGST. Again, may be due to Backblaze quarterly report cause they dont show any UltraStar branding, they use HGST.
( Stupid Westen Digital )
Whereas, if some WD drives explicitly say HGST and some don't, you can just buy the HGST ones.
(Very closely analogous to smartphones that have the same exact model name, but which vary between Snapdragon and Exynos SoCs depending on the precise model number that only appears in fine print in a few places. When buying one of these phones used, you often have to google the precise model number to figure out whether you're getting a fast phone or a slow one!)
I started with MicroG 3 years ago, and there is no way that I'm going back.
https://en.wikipedia.org/wiki/Deskstar
https://en.wikipedia.org/wiki/History_of_hard_disk_drives#Ma...
Side note, does Backblaze not run any enterprise or datacenter SSDs?
That helps quite a bit because it reduces the outer-bound of how much data can store with us from typical Mac/PC devices. Granted we do have people with 80+TB backed up with that service, but that VAST majority store A LOT less. The average is low enough that we can continue to provide the unlimited service - kind of like a buffet model. Some will eat more, most will eat less and buy a drink (Extended Version History).
Keeping it to Mac/PC only does make Linux, NAS, Server folks unhappy, but thus far no one has been able to crack the code on an unlimited, fixed-rate service that can back up those devices economically, but if we figure it out we'll let folks know :D
Please do! I really would prefer to use Backblaze.
In the meantime, CrashPlan for Small Business is an unlimited, fixed-rate service that supports NAS backup on macOS and Linux. I depend on it to backup a lifetime of photos (100K+), for example.
https://support.code42.com/CrashPlan/6/Backup/Back_up_networ...
Expecting vendors to live up to their marketing claims is not abusive behavior; it's the cornerstone of markets based on informed decision-making by both buyers and sellers.
Edit: I just saw that another employee mentioned the largest customer is storing 430Tb. That's pretty darn unlimited for the price point.
> the economics just don't work [for Unlimited] long-term due to people who abuse it. How does this apply to Backblaze's unlimited backup service?
So far, it has worked out for us (going on 14 years now). If you are curious about the size distribution of our customers, here is a histogram of our Personal Backup customer data sizes from the end of 2018: https://i.imgur.com/iVEuwUT.jpg (You will need to zoom in to see all the data points - the largest customer stores 430 TBytes for $6/month.) Backblaze never raised any funding, we're self sufficient with no deep pockets, so it works for us financially.
Just to be clear, Backblaze doesn't price the Personal Backup product as $6/month for an unlimited amount of storage to attract gigantic customers. Our driving force for almost every decision on the Personal Backup product was to make it "easy" for people who either are not experts at using computers, or just don't want to spend a lot of their time on it. My 88 year old father doesn't know the difference between a MByte or a GByte or a TByte, and he would be stressed out worrying about "paying per GByte". The fixed price of $6/month is intended to reduce "sales friction", not attract massive storage customers. Another issue for non-computer-expert customers is they don't know where all their files are. So to make it "easy", Backblaze simply backs up EVERYTHING by default, and only excludes things like the Operating System if we absolutely know what it is and know it can be recovered in other ways. So the Backblaze Personal Backup product can be installed with a username and password, ZERO CONFIGURATION, and the customer's data is backed up. But that wouldn't work very well if we charged per GByte, customers would think we were doing it just to increase how much they are charged. :-) So the "fixed price for any amount of storage" is part of the overall "easy to use" strategy.
What we ask of our above average storage customers is that they recommend the product to their less technical friends with less data. We get a good reputation by supporting the large customers, and those customers are often the "technical mavens" that recommend products to their friends and family.
I work on the Personal Backup client that runs on your laptop. Personally I like the super ultra big customers simply as quality assurance. If I can keep the client running for a customer with 400 TBytes, it will absolutely purr like a kitten for an average sized customer with 1 TByte of data.
This article says Backblaze uses SSD a little bit. Somehow, I remember they used Samsung branded SSDs and they had very few failures that weren't DOA, but I can't find the relevant article, so that memory might be entirely fabricated.
Would love to see failure rates on SSD brands.
Are there any other examples of companies doing similar releases of valuable internal data?
If they never did these I wouldn't even know about their existence. It is all apart of long term marketing and branding.
For sure - I can't think of any other companies with a similar approach to things though. I appreciate what they do, and the good quality write-up they provide as well.
If I remember right, years ago YouTube was releasing their prior year server build. I recall things like a cool air stream being directed right at the processor, rather than cooling the whole room enough for traditional cooling methods to work well. My Google fu isn't finding the blog posts I remember reading, probably from ~2010 era.
the early OkCupid blog was really good at this
This one has always stuck with me (archive version: https://www.gwern.net/docs/psychology/okcupid/whyyoushouldne...)
> It turns out you are 12.4 times more likely to get married this year if you don't subscribe to Match.com.
more archives: https://www.reddit.com/r/gwern/comments/aapn1l/okcupid_blog_...
In addition to usage patterns, there's a lot more that contributes to mean time between failure of hard drives; like operating temperature (ambient, fluctuations, max), relative humidity, vibration and alike.
There's also well researched and published literature around this.
From Microsoft 2016: Finds relative humidity to be the dominant factor for disk failure https://www.usenix.org/system/files/conference/fast16/fast16...
From UToronto 2012: Finds no correlation with DRAM failures, nor high temp and disk failure but concludes temperature variability affects disk reliability more than maximum operating temperature http://www.cs.toronto.edu/~bianca/papers/temperature_cam.pdf
From Google 2007: cannot find strong correlation between failure rate and temperature or utilization. https://static.googleusercontent.com/media/research.google.c...
From Microsoft 2013: focuses on operating temperature being the driving factor of failure, more than load. http://www.cs.virginia.edu/~gurumurthi/papers/acmtos13.pdf
I quote - >Note: The Seagate 16TB drive (model: ST16000NM001G) does show 59 drives and is listed in the report because the one failed drive had not been replaced at the time the data for this report was collected.
How can we be back to zero drive failures?
It's comforting that some things are consistent between the enterprise and consumer worlds.
Bought about thirty H....4040ALE640 units several years back and they've had fantastic reliability. No failures, and IIRC only one's been replaced (as a precaution after its SMART Reallocated Sector Count ticked up). And no RAID hiccups whatsoever.
I compared it with the April 1 data set and it which appears to have 60. Serial number ZL202NFZ appears to be dropped in the later version and serial number ZL202400 seems to not be reading as at April 1 but is available at a subsequent date.
Just curious what's going on here! I recently received one of these and the backblaze drive data was very helpful with my evaluation.
https://www.cdw.com/product/hpe-hard-drive-600-gb-sas/450348...
We have a few of their machines and I've always been curious but haven't been able to find much.
*Edit -> For giggles here's an OLD post where we dissect drive failure and talk about migration a bit -> https://www.backblaze.com/blog/3tb-hard-drive-failure/
Q2: https://www.backblaze.com/blog/wp-content/uploads/2020/08/Q2...
Q1: https://www.backblaze.com/blog/wp-content/uploads/2020/05/im...
Are they just cheaper?
HGSTs are in short supply states-side right now and in high demand. Toshibas are also in limited supply here (at least the desirable helium-filled ones) and are about 2/3 between the Seagates and HGSTs.
Also in their product, drive failure is okay!
I grabbed 2x14TB Seagate EXOS drives for $250USD each.
A 14TB WD Ultrastar looks to be a bit over $400USD each.
For 25% more you can get 200% the capacity with the Seagate drives. So for 25% more I can run RAID1 and have redundancy versus a single WD Ultrastar.
They have a solid system set up for the installation and replacement of large numbers of drives on a regular schedule and the way they segment data would require multiple drive failures to cause data loss (I think it used to be 3 drives out of 20, but don't quote me on that). A slightly higher failure rate on a noticeably cheaper drive still works out in their favor financially without adding significant extra risk.
Curious if you have any impression of Toshiba's MN series? Especially the helium-sealed ones look compelling with their lower power consumption.