You can also create a write-only key. If you run tarsnap from a server which gets pwned, the attackers can't touch the existing backups. Don't be the next Astalavista[1].
[1] http://joncraton.org/blog/49/analyzing-the-astalavista-hack
You can also create a write-only key. If you run tarsnap from a server which gets pwned, the attackers can't touch the existing backups. Don't be the next Astalavista[1].
[1] http://joncraton.org/blog/49/analyzing-the-astalavista-hack
If you're paranoid about it being closed source, you can make a quick script to encrypt sensitive data, copy it to another folder, then sync that encrypted folder online. I do something similar with a small % of my data.
As far as server backups, it's trivial to script a copy to your local machine then let Crashplan sync that.
So far as I know, nobody else has done that.
In practice tarsnap is cheaper than everything else because of the dedupe.
Crashplan does dedupe and compression but has UNLIMITED storage/bandwidth for one price.
He also has a bug bounty http://www.tarsnap.com/bugbounty.html, and several substantial security bugs have been found and fixed due to the bug bounty (http://www.tarsnap.com/bounty-winners.html). In fact, the first of those, the AES CTR nonce bug, was found before he had offered the bounty program; the bounty program was inspired by that bug, and has since led to the discovery of several other more minor issues.
So, the source is available, and there's a bounty out for discovering bugs ranging from cosmetic issues to major security issues. Feel free to review it and submit any bugs you find!