What do people like for backups these days? Crashplan seems pretty damn good to me.
What do people like for backups these days? Crashplan seems pretty damn good to me.
They've made an awesome product and they provide it at an awesome price.
Previously, I was a user and big proponent of Jungle Disk, but that product has become all but completely abandoned since being gobbled up by Rackspace. (I love how their solution to comments about going radio silent and not updating their blog in over a year was to just take the blog down and put up a "The Jungle Disk blog is currently unavailable" message, as if the blog were just temporarily offline. One of their last blog posts was a "Future of JungleDisk" post, outlining tons of features that, 16 months later, were nowhere to be seen).
I had been recommending Carbonite to friends and family for an easy-for-normal-people backup solution, but their performance falls short of CrashPlan, and their heinous near-silent default exclusion of video files from backups would have led to serious tears if we had ever actually needed to restore from backup. (Automatic backing up of video files is reserved as a feature for the new $150/yr HomePremier plan - which at least now makes this fact somewhat visible. Previously, there was damn little to indicate that this exclusion was happening). That made Carbonite something much less than the "set it and forget it" backup for my non-technical friends and family that it was supposed to be.
CrashPlan is nice and friendly, has no hidden "gotchas" that I have found yet, and has a great PRO service as well. The client GUI can even be made to connect to the daemon on a headless server through an SSH tunnel, just with a simple change in port number in the config and forwarding the remote port through the tunnel.
Hm.
And after you've logged in to Crashplan, it's not clear to me that you can do a whole lot of damage via the website; the password used to encrypt your data is specified on the client side, and there is no reset mechanism for it. I mean, they could update the credit card settings, or modify the configuration options like excluded directories or send rates, but not a whole lot else.
Also, you can just specify your own encryption key. Everything is encrypted locally.
It seems like they should be holding on to files for 30 days period or something. Does anyone know?
(I do like CrashPlan, but this seems to be common practice with data storage services.)
Removing the computers associated with a CrashPlan account and then cancelling the account looks like it'll cause a pretty big headache.
Backblaze really shines if you have a single Windows or OS X PC with a lot of data. For $50/year, it will allow you to backup unlimited data for a single computer. As far as I know there is no student discount.
SpiderOak really shines if you have multiple Windows, OS X or Linux PCs with a small amount of data between them. For $100/year, it will allow you to store up to 100GB of data between as many computers as you want to back up. If you're a student, it will only cost $50/year.
"Wuala is completely private and secure. When you store a file in Wuala, the file [..]gets encrypted before it leaves your computer. [..]Your own password is very important here: it never leaves your computer, so we do not know it. Hence, not even we can access your data."
- https://www.wuala.com/en/support/faq
But it seems pointless in light of:
"Do you plan to open the source code?
Currently not. Opening the source code of Wuala would consume quite some time and effort, and commitment to maintain it. If you are a software engineer and would like to see how Wuala works, feel free to apply for a job at Wuala."
- https://www.wuala.com/en/support/faq/c/21
It would be trivially easy for them to hide a backdoor and/or leak data in their closed-source code. So at the end of the day, the message is "Trust us." So what purpose does the client-side encryption serve? Empty marketing. At best, it makes it _slightly_ harder for them to read your files.
Tarsnap (www.tarsnap.com), which does have client source code available, doesn't suffer from this problem. Unfortunately it's a fair bit more expensive.
Also, please note that laws are often constructed such that companies can be forced to hand over data they possess, however not to collect data they do not possess yet. E.g. there are many laws in many jurisdictions that could be used to force Google to hand over data you have stored in Google Drive, but the same laws cannot be used to force us to add a backdoor to Wuala. So legally, it is much much easier to obtain data stored in Google Drive than to obtain data stored in Wuala (or another service that uses client-side encryption). Noone has ever asked us to add a backdoor to Wuala and we would fight against it if someone did.
I agree that it would be nicer to open the source code so our security would be independently verifiable, but claiming that what we do is "empty marketing" is clearly wrong.
For why not to trust a closed-source system's claims of security, see Skype. If I remember correctly what I have read, they boasted about using "end-to-end encryption", strongly implying that your Skype calls could not be wiretapped. The catch? The encryption keys were stored on the server! And there was a story where someone (a drug smuggler, I think) was busted seemingly as a result of intercepted Skype calls. The misleading claims of security didn't ruin Skype's reputation - people still use it.
I'm glad you replied to my comment as it shows you're at least thinking about these things. I hope you will consider opening your source code in the future. At that point Wuala might be of interest to me.
Full story, from last fall: http://prog.livejournal.com/983354.html
I'd be curious to hear more about other people's solutions.