Turn your old, cracked Android phone into a backup server
hannahtech.co
hannahtech.co
— Me, 2½ years ago: https://news.ycombinator.com/item?id=18019343
NO.
You need security patches. The current "regular updates" bullshit where the Play Store wants to update and app I updated an hour ago is insane.
So… YES. Regular updates to all of its software is how you stay on top of security updates.
This is a problem of their own creation, trying to tell users to accept it anyways is a non-starter for many.
There are certain apps that I will update though, like Element, but I don't even update Firefox because the new engine breaks too many things for me, like extensions and bookmarklets. IE: Last time I checked you could only choose between 12 extensions on the latest Firefox Mobile.
That's a load of garbage.
I don't do updates and zapped all google services except the playstore. Been looking good since.only whatsapp is the only culprit that demands me to update by force.
WordPress can do it. Others also could, if they wanted to.
But for various reasons they don’t, and that’s the problem.
But if you don’t update at all, you will be subject to an exploit, and you and your devices will then possibly be unwitting members of (possibly multiple) botnets.
You might need it if the screen cracks and you want to save data off it.
Sometimes there are ways around it by dirty booting a recovery image, but it's not as simple as it sounds, and you'd need an unlocked bootloader to do so: https://petermolnar.net/article/save-files-from-a-dead-scree...
Nearly every phone today is sold with a USB C port.
"But this phone is older than..."
My Moto Z Play was released in 2016. That phone is now 5 years old. It came with Nougat... and I can mirror the screen with a USB C hub with Built in HDMI. Plug in a mouse and you're done.
No need to leave adb enabled, which is a security hole that can be exploited by unsafe USB ports and bad actors. (Also, police.)
Which adapter did you use?
Even did a video: https://www.youtube.com/watch?v=Qkh4oagFfb8
Got out my old Moto Z Play which was retired. Restarted the phone so I couldn't use fingerprint to unlock.
Plugged in a mouse, clicked pin. Unlocked.
Moto Z Play runs Nougat, stock but rooted. You don't need root to be able to do this nor do you need ADB to be enabled.
Also confirmed to be working on Razer Phone (stock, 9/Pie) and Essential Phone (stock, 10). Also works with Keyboard instead of mouse. Just type in the pin and hit enter.
Pattern unlock will have to be done with the mouse for obvious reasons.
So if your digitizer is completely busted, you can still use a mouse and keyboard. If your display is completely busted, you likely will be able to get video alt mode with USB C out.
I tried it on a few other devices that I had in my pile. Chances are, if it's Micro USB, you won't get video on boot, even with a proper MHL adapter.
* Sony Xperia J (Jelly Bean): Nothing, Micro USB
* Sony Xperia Play (Gingerbread): Nothing, Micro USB
* Marshall London (Lollipop): Mouse and Keyboard Works, Micro USB
* Asus Zenphone 3 Zoom (Nougat): Mouse and keyboard works, USB C
IIRC, Displaylink and OTG support was officially added in Lollipop, so that kind of jives with my experience here. As always, YMMV.
No, adb is still needed.
You would still be able to use a mouse or keyboard to input a pin or passphrase if the screen was still semi readable.
With a USB C port, there's a near absolute certainty that you can simply plug in a USB hub with HDMI built in to hook your phone up to a mouse and monitor to get around the cracked screen issue.
Cracked screen AND USB-C port failure. No charging or data transfer possible.
Apparently at one time google opted me in for Google Photos, so I have a backup of those, but recent contacts were totally lost.
Still have the board lying around and am tempted to continue tinkering with it... Or would be if I had any clue where to get insight on how to do advanced debugging on why a mobile phone wouldn't even register as connected over USB-C. Assuming some sort of handshake failure.
Or preferably use Syncthing or any backup plan.
Data you have in one place is data you don't want.
There's obviously benefits to doing so, but it has some big costs?
eeeeerm, no. It didn't get better at all. It basically wiped out a vibrant 3rd party android development culture by making it extremely hard for them.
Did you install a custom bootloader to load your ROM and root apps? Cool, but as a consequence of that, anyone who connects a USB cable to your phone can get into anything in it. Does it supposedly have security? Wanna bet the quality of any security in a homemade app vs Google's best efforts?
All arguments have multiple sides to them.
No root, no fuss.
That's the system in currently using, at least. I'd be happy to read about other open source solutions if anyone has a better solution. My backup system is geared towards a service that exposes nothing more than SFTP or WebDav as a backup location because of a cheap cloud storage subscription I've managed to get.
- It can only do one set of backup settings and consequently only one backup destination without additional tooling, which is not Right™.
- It cannot add different prefixes to the names of index and data files, making it impossible to set up S3 lifecycle rules for dumping the latter to Glacier. (Duplicity requires the former to be hot for some reason, I don’t know why.)
Both of those are things you can do with the underlying Duplicity tool and a scheduler, but the UI does not expose them. Thus I sadly had to discard Déjà Dup’s shiny GNOME UI, and I know of no other backup tool with a shiny GNOME UI (and am too lazy to write one so far).
Have any parts of this become false?
Please, run your backup servers on machines designed to do so, capable of receiving regular software updates, etc...
If anyone had some tips on how I could get into these machines it would be much appreciated.
Because right now i'm just using consumer hardware (an Athlon 200GE for its low 35W TDP, some cheapo RAM and a number of Seagate BarraCuda HDDs) in combination with Debian, which also runs on my other cloud servers. It's all mounted on my other devices either through SFTP or a Nextcloud instance that's also running on them for easier file replication. I don't even have RAID or ZFS/XFS/Btrfs file systems, just ext4 because any sort of clustering would introduce unneeded complexity to the setup - instead, a cron job with rsync backs the data from the "primary" HDDs to "secondary" ones every day in an incremental manner (well there's also BackupPC that does network rsync backups across servers).
What purpose would running a NAS oriented OS distro even serve, for simple uses cases like that? It feels like the current "ad hoc" setup is really affordable and easy to operate.
I think a SoC would also be nicely suited for this, as long as there is sufficient I/O capability. In regards to phones, however, i feel like drivers for obscure devices could probably become problematic quickly.
- ECC RAM, to avoid corruption on write
- Software RAID, to avoid data loss due to drive failure
- Some kind of checksumming and error-correcting filesystem, e.g. ZFS, to prevent data loss due to bad sectors
- Enough CPU to transcode media in real-time
- Vanilla distro with SSH, SMB filesharing, Plex, and networked printing
- A spare PSU in the closet
I explicitly avoid:
- Hardware RAID (unnecessary, expensive, harder to fix)
- Any OEM prebuilt NAS products (more expensive, less capable, less user control)
- Any specialty NAS-oriented distros or OSes (more feature bloat, bigger attack surfaces)
I use plain old Debian for my home NAS. I'd switch to OpenBSD in a heartbeat if it supported a checksumming and error-correcting filesystem.
Ok it's old but: raid is not backup.
I've personally worked for a small online shop that was selling digital items and shut down when their raid failed. Of course, they had ignored my warnings to build a mirror system or do copies on removable drives or ... anything resembling an actual backup.
Edit: that said, I do have a box that's pretty similar to what you're describing.
I back up my family photos and other important files to Amazon S3 using Restic. My 150GB of data ends up costing me about $1.50/month. I could get the price down lower if I use, say, the Infrequent Access storage tier, but at that price point I just can't be bothered to deal with it.
A free tier often isn't worth it if you have to put any time into thinking about whether you'll exceed the limit. I'd just go with a cheap pay-as-you-go service and not worry about it.
So you recommend ZFS but not TrueNAS? It more or less is FreeBSD with zfs and NAS-oriented defaults+utils. There's not much I'd count as bloat.
- power management
- semi-closed source applications
On power management, I don't use the NAS box continuously, and there can be long gaps between accesses. Having the box "sleep" for 95% of the day, and wake up the disks only for one or two bursts of activity is interesting to me.
I tried doing that with DIY solutions, including Raspberry Pi+SATA disk type of arrangements. Overall it didn't work great and was a PITA.
On the semi-proprietary apps, I am thinking about Synology's apps. I could totally live without them, but it's a nice addition to the package, they're easy to install, seem to be well maintained and work decently well.
Have you really managed to get that to work? I got a QNAP TS-230 a few months ago hoping I could do just that, but it turns out that even this smallest NAS box they are offering isn't really designed with this "occasional use" in mind. There are so many user questions about this (https://www.qnap.com/en-us/how-to/faq/article/why-are-my-nas...) that they even built a half-baked utility that's supposed to give you a hint which process is preventing the drives from going into sleep mode, but it's not a great help. I have disabled all services (photo indexing with face recognition and other such crap) except for the most basic ones, but still the drives are happily chugging along, flashing their LED every few minutes, not spinning down. I know that it's basically a Linux computer, and there are probably utilities I can install to diagnose the issue better than with the above-mentioned software, but isn't this something that's supposed to work out of the box, or at least be easy for an average user to accomplish?!
I run relatively few stuff on it too, with no client that consistently access the shares though samba/nfs (I cluster the scripts that run automaticaly around the same range of time, and they unmount after they’re done).
I wonder if your system is not writing logs from a monitoring service (something checking your dynamic DNS, or waiting for remote connections, or pinging the internal servers to see if they’re alive).
I stopped most default services, including sync (it’s done more rarely via a user script instead), and yes, it can be a PITA to understand what’s running out of the box.
As you said, it's very low energy and zero noise (rubber feet and quiet fan).
It's also effortless to set up and run with their RAID system and syncing etc is very good. It'll let me know if there is a problem with a drive, it keeps itself updated and I've never had to reboot it.
I do not use it for Plex as it wouldn't be able to handle it. They are a bit under powered but they're very optimised for their main purpose, Network Attached Storage, and that's the most important thing for me.
It is also very neat and tidy, unlike most home made solutions.
I keep eyeing OMV but haven't splurged on running a NAS with multiply-redundant drives separate from my application server; currently it's just an RPi4 as a docker host, with rsync keeping two USB drives in sync with each other.
For instance trying with an old low profile PC, wake on lan didn’t work half of the time so I gave up, and just let the drives sleep. But they would also fail to wake up sometimes.
All in all a NAS is not that expensive (I have one I bought for 400 or so, and it’s lasting for 15 years now…), so it’s hard to justify the endless tweaking of a solution that could work the same if done well.
BTW even with a commercial NAS , ssh access is configurable, major scripting languages are there, and recent ones have docker I think. For the really custom stuff, like you I use Raspberry Pis that mount the NAS files as needed.
But then I'd need to find a RAID enclosure and a something to run OMV on. The NAS was around £150 with all that built in
just one nitpick with your setup:
if your primary hdd corrupts, rsync will not notice/care and corrupt your backup as well. zfs is all the rage because it aims to have two sources for the data aswell as a checksum, so it can tell which data-source is flawed AND fix it.
Right now i have incremental backups over the network with BackupPC: https://backuppc.github.io/backuppc/
That software solution sort of dances around the issue, because if any files were to become corrupted, i could just go back in time to their older versions, though that approach isn't necessarily good either - since that means having to store the original "full" backups for a long time and also takes up more storage, which i do for the essential data, but not the stuff that i'm willing to lose. And, since the data stored can be arbitrary and therefore checking for corruption would have to be done manually, there are serious drawbacks to that, in regards to even knowing when things have gone wrong.
Of course, there's also the possibility to use additional sources of redundancy, like versions within Nextcloud should the actual file contents of a particular version become corrupt, however for certain scenarios file systems like you've described indeed do become the way to go. Maybe not for every homelab out there, though.
Not (really) true, there is not much hard data backing this up as I see it, and for what there is, the retention would be 1+ year. The thread is not about offline backups, but an always powered backup server anyway. And SSD does make sense for a lot of reasons: HDD speeds are likely slower than local CAT cable, the higher IOPS helps on parallel workload cases, not to mention the way lower power draw and zero noise (no moving parts for the rest of the setup), compared to a chirping HDD.
Once you have usb debugging, I can recommend Vysor, super easy to use to control your phone from the pc.
I'd also recommend turning on Talkback (assistive technology) and VoiceAccess as that can help you use the device even if you cant see anything on your screen. That helped me a lot with my phone that has a broken screen where nothing but the touchscreen works.
Re-enabling USB debugging was the following process:
1. use USB-OTG to go into the bluetooth menu to connect a bluetooth device to.
2. enable usb debugging using mouse
3. connect to PC and use the bluetooth keyboard to allow USB debugging
4. use scrcpy to control the device
Obviously this only works reasonably well if you can see at least some portion of the screen.
Will forget about it. Not really that interested in wireless anyway.
Of course, my Buffalo NAS can’t compete with that and got fewer updates than my old phone…
It is no longer connected to an internet facing network.
Using it for my router, firewall and NAS hardware - and can totally recommend it.
Vendor kernels are a continual security apocalypse that never ends.
That said, with some magic linux command sauce, external drives can be used(part 2 of link), then software RAID, offloading data to them to prolong flash writes lifetime, then more stuffs like AnLinux can instead be used to add functionality to it.
Interesting read indeed.
someone can find 10+ yrs NAS really cheap nowadays.. I ve got a ..bucket of Netgear's (most of them ReadyNAS Duo v2) for £5 each!!!
don't you have problems with SSL certificates and accessing the interface via browser?
In general, both a router and a NAS do lack the backup battery, unless an UPS is also used...
It's pretty neat! Check it out if you have a need for it.
Would this software also work in that environment?
https://github.com/Magisk-Modules-Repo/acc
I had my phone plugged in for almost 3 years, and the battery still lasts for 3 days on its own. Highly recommended.
As a side note, can someone tell me if something like this can be made for postmarketOS? I installed it couple months back and this is really bugging me. Apart from constant vibrations.
In theory, if changing charge thresholds is supported by the PMIC (power-management IC) driver, it should be exposed in the sysfs. It is device-specific though, and might not be exposed by the driver.
I know you're joking, but I've seen this logic at play elsewhere.
READ the documentation though, because opening devices up for the internet can be nasty, especially when it's your first time doing so.