Backblaze Hard Drive Stats
backblaze.com
backblaze.com
They're massive beasts, with 9 platters and 18 heads, but enabling acoustics and power saving really helped on the seeking noise level.
Not sure how much of a performance hit that leads to though, haven't had time to fully investigate.
They run significantly cooler than the 8TB Reds tho, from ~45C down to ~30C in the same bays.
Do you know what's the approximate power draw (in Watts) of each drive with these settings enabled? I'd like to move to a lower power system sometime in the next year, but I'll also need to add some more drives. Power is extremely expensive where I live.
I wonder if the power saving features reduce the drive lifetimes (because of quicker spindowns)... might not be a good idea for an always on NAS.
I do not, but I could find out as I have a external SATA to USB adapter with separate 12V power. Check back in a day or so.
> I wonder if the power saving features reduce the drive lifetimes (because of quicker spindowns)
Ah, I enabled max power-saving without spindown. Most of my earlier HD failures, including a couple of WD Greens, taught me to avoid spinning down.
I tried running with both the power management set to "Level 128 - Minimum power usage without Standby (no spindown)" and Acoustics Managment to "Maximum", as well as "Disabled" for both. Didn't make a noticeable difference on power draw, at most 0.1A more during writes, primarily just noise.
Idle
5V 0.27A
12V 0.40A
Write
5V 0.53A
12V 0.50A
So that's just over 6W idle and 8.7W under load. I'm surprised about the high idle draw, both due to being significantly higher than the specs[1] and due to them running so cool. Did they spin down the disks to get the 4W figure perhaps? I did check my clamp meter against my electronic load and it reads pretty accurate.I didn't manage to test reads properly, since the disks are part of a ZFS pool and it spreads the reads all over, along with aggressive caching.
[1]: https://toshiba.semicon-storage.com/us/storage/product/data-...
Read/Write – 6.2 W
Idle – 3.0 W
Standby and sleep - 0.8 W
Which strikes me as pretty reasonable. I suppose I'll stick with those since I can rip them out of EasyStores.For idle the datasheet says 4.53W typical, however I admit my disks were idle only for a few minutes when I did my readings as dinner was almost ready, so possible they would go lower after longer idle periods.
- the enterprise ones that are meant to sit in a datacenter. They offer the best performance but are noisy and power hungry.
- the SOHO ones, that are often 5400 rpm. They are lower performance but optimized for noise and power consumption.
I ended up with ST6000VN001 and the noise level is very reasonable.
And thanks to the better thermals, due to the helium, I can reduce fan speeds significantly as well.
For Linux it seems hdparm[1] is the way to go.
[1]: https://linuxconfig.org/how-to-reduce-hard-drive-s-acoustic-...
I have eight 3TB Reds, so far I've had two of those developing pending sectors after over 6 years of power-on time (no spindown), and of those one developed uncorrectable sectors a year later and I replaced it. The other one is chugging along happily so far with 27 pending sectors.
In the case of the WD Red, it went from pending sectors to failing SMART self tests in less than two weeks.
So yeah, disappointed about the short life span.
I liked the tone and approach of their old blog posts but this is pretty cool too. It’s just good to see them continuing to share their data since it’s arguably relevant to a wide range of audiences.
It's just the central landing page that Backblaze has had all of their HDD stats and blogposts linked from for years now[1].
[1] - https://web.archive.org/web/20190707132216/https://www.backb...
I recently needed to expand (to the point I am at now) and bought & shucked 14 TB WDs, so I'm curious to see whether there will be any long term difference in terms of reliability between the "official" red drives and the shucked whitelabel drives.
It may seem like they are running fine, but are they actually? Have you run a zpool scrub or equivalent?
What happens with these old drives is that one dies and then you have to replace it, which is very hard on the other drives as the array is rebuilt. Then while the array is being rebuilt, another drive dies. It's better to replace drives when they are EOL (usually 4 years if running 24/7) rather than waiting until there is a problem.
The vast majority of SMR hard disks are 6TB capacities and below, and I'm only aware on one 8TB Seagate SKU that is SMR. Though I'm aware HGST shipped a 20TB SMR drive late in 2020.
NAS Compares has a fairly good starting list of drives and whether or not they are CMR or SMR, though there may be more exhaustive lists out there: https://nascompares.com/answer/list-of-wd-cmr-and-smr-hard-d...
-- -----
In general, check the R/N of shucked white-label drives, and you should be able to quickly find a corresponding datasheet (hundreds of pages) from the manufacturer.
For example, some 16TB WD Elements I'm in the process of testing after shucking are R/N US7SAR160, which are 16TB HGST Ultrastar DC HC550. These are SATA 6Gbps 7200rpm helium-filled CMR drives with 512MB of cache.
Edit: arguably the blog post was put up in 2021, but something to indicate that it's old news would be useful. https://www.backblaze.com/blog/backblaze-hard-drive-stats-fo...
[edited to sound less snarky]
Of course that has both performance and data corruption scenarios that one needs to take into account.
:D
What they should do is make you cut a half a million dollar check, refundable when you spend half a million dollars on services.
It removes so many headaches from dealing with people who think their $100 over a year is Very Big Money.
Actually I would expect that such a big company have these things readily available on request.
If a company ask me for similar paperwork (which they have) I have the paperwork in order and ready, they sign a NDA and I am sending them. It's just a step in the sales process imho
A company that never did a pen test or security audit or doesn't want to share them doesn't give me much trust to use them as a partner.
In this case it's not so much about a $100 spend, it's about them potentially leaving a lot of money on the table if they are incapable of delivering the reports in question.
Based on what I have experienced, those that have real decision making power in companies that will make a high six to seven figure purchases simply do not have time to vet their home projects where they are going to spending $100/year. The grandstanding arguments about importance of their projects come from people who probably won't even spend $100/year
You make it sounds this is ridiculous to do a security assessment or to ask for such paperwork. I can tell you that my company insurance even demands it. At the moment I prefer to pay 3x more and store things at a cloud provider which shares these kind of documentation.
https://www.backblaze.com/blog/privacy-update-third-party-tr...
Now while I certainly agree that I don’t like this info leaked, there was no mal-intent and they quickly took action once notified. I feel like their action is what makes me like them so much.
For one, this highlights they don't have automated tests detecting arbitrary/malicious JS injection on their web app. This is a serious security risk: we are talking about your cloud filesystem here, and "spear phish / bribe your marketing intern to adding malicious.js" is a real attack vector.
Alarms should be going off internally whenever a new external JS file gets included in your webapp, either ststically or dynamically. Facebook pixel today, a malicious hacker tomorrow.
I'd expect a private cloud to have better security procedures than "wait till someone on Twitter discovers a bug".
(Personally, I will continue to use Backblaze, but just highlighting why it's a serious security concern.)
But the specific issue I see is that a piece of external JS got inserted into their web app, and their security team didn't realise it.
The fact that its from GTM is no excuse: give me Google tag manager, I'll exfil your users data in an hour ;)
Injecting third-party content then requires editing both your site and the server setup. Of course, you can make the policies more or less strict depending on how much you want to tighten this kind of attack vector.
This is a weird metric.
When a company provides full disclosure people are shocked and abandon the platform.
Every company has bugs. Everyone eventually gets breached. If a company is honest with what happened, follows up with their users, and fixes it, what more can you ask for?
Should it have happened? No. Did they find the issue? Yes. Did they fix it? Yes. Did they disclose it? Yes. Perfect, thanks.
edit: and enabling facebook tracking on customer pages...
I mean, worst of all, many of them are Web Developer means there is a very high probability they have make mistakes /bugs in the pass, big or small. Which put them in the category of hypocrite.
Backblaze is the most affordable and available remote storage/cdn service available, by miles. Go look at a calculator between amazon and backblaze.
The actually give half a care and even partner with various providers so your outgoing bandwidth is free to them.
Other services doing worse things is not an excuse. I don't want to go with amazon either, hence my question here.
But they don't work with them. They have to it in order to run ads and as result to survive.
Please provide specific sources of AWS, GCP, or Azure leaking file names and sizes to a third party.
I speak of Windows and Mac users who got a Microsoft 365 subscription for the Microsoft Office apps. That comes with 1 TB of OneDrive, or 6 TB if you get the family subscription.
OneDrive has API access which is supported by a fair number of commercial and open source backup programs.
You can get a family subscription without being a family. All you actually need is the ability to control 5 extra email addresses, one for each fake family member. Your 6 TB would end up partitioned into 6 1 TB buckets so as I said, would be somewhat of a hassle to use.
But if you only need 1 TB, and want or need Office anyway, and don't really have a lot of non-backup cloud needs, then OneDrive is a good, often overlooked option.
For me anyways, this is a tertiary backup of data that is duplicated in a zfs raid 10 pool and in external drives at a different house. A high request cost isn't much to get back my family photos, documents, etc, in a situation where neither of the first two backups are available.
https://www.backblaze.com/blog/privacy-update-third-party-tr...
IMHO, over-ado about a small something.
"A new campaign was launched beginning on March 8, 2021 on the marketing web pages using Google Tag Manager which included the Facebook pixel. That new campaign resulted in the Facebook advertising pixel being accidentally configured in Google Tag Manager to run on all platform pages instead of just the marketing web pages."
"We’ve confirmed that there was only a single page (b2_browse_files2.htm) where the Facebook advertising pixel had the ability to access certain metadata. We tested this on Chrome, Safari, Firefox, and Edge. Our investigation determined that 9,245 users visited that page during the window when the Facebook campaign was active (March 8 at 12:39 p.m. Pacific time, through March 21st at 11:19 p.m. Pacific time when we removed the offending code)."
"If users were browsing their B2 Cloud Storage files on b2_browse_files2.htm during that period, AND clicked to preview file information, then the Facebook pixel pulled the following metadata: folder/file name, folder/file size, and the date the folder/file was uploaded. The folder/file metadata was limited to file information that was currently loaded in the browser.
No actual files or file contents were shared at any time. The data that was pulled did not include any user account information."
> We use Google Tag Manager to help deploy key third-party code in a streamlined fashion. The Google Tag Manager implementation includes a Facebook trigger. On March 8, 2021 at 12:39 p.m. Pacific time, a new Facebook campaign was created that started firing a Facebook advertising pixel, intended to only run on marketing web pages. However, it was inadvertently configured to run on signed-in pages.
[0] https://www.backblaze.com/blog/privacy-update-third-party-tr...
It looks like it does but the permissions are so frustrating to use that it just becomes overly permissive as a side effect.
The rest of my stuff is in S3 with Glacier auto archives.
The reading/writing speed of tapes is excellent, better than that of hard drives, so writing a backup takes less time.
For archives that are accessed only infrequently, tape is more reliable and also faster.
If you want to have access in less than a minute to any part of your backups, then yes, tape is inappropriate and you must use HDDs.
Tape is still the best backup medium for many small and large companies.
And by the way, how fast do you think a service like Backblaze is?
I use Backblaze and Wasabi.
No, they do have redundancy.