[146470] in cryptography@c2.net mail archive
Re: [Cryptography] Keeping backups (was Re: Separating concerns
daemon@ATHENA.MIT.EDU (zooko)
Thu Aug 29 16:41:02 2013
X-Original-To: cryptography@metzdowd.com
Date: Fri, 30 Aug 2013 00:21:54 +0400
From: zooko <zooko@zooko.com>
To: "Perry E. Metzger" <perry@piermont.com>
In-Reply-To: <20130829133035.1dd95092@jabberwock.cb.piermont.com>
Cc: Far? <fahree@gmail.com>, Phill <hallam@gmail.com>,
"cryptography@metzdowd.com" <cryptography@metzdowd.com>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com
On Thu, Aug 29, 2013 at 01:30:35PM -0400, Perry E. Metzger wrote:
>
> So, as has been discussed, I envision people having small cheap
> machines at home that act as their "cloud", and the system prompting
> them to pick a friend to share encrypted backups with.
The Least-Authority Filesystem is designed for this use case (among a small
number of other use cases).
> Inevitably this means that said backups are going to either be
> protected by a fairly weak password or that the user is going to have
> to print the key out and put it in their desk drawer and risk having
> it lost or stolen or destroyed in a fire.
In LAFS, the keys are strong, computer-generated keys, so you have to print
them out or write them down. Printing them in triplicate and storing them in
separate locations seems like a good trade-off of the risk of theft vs. the
risk of loss, for the reasons you give:
> I think I can live with either problem. Right now, most people
> have very little protection at all. I think making the perfect the
> enemy of the good is a mistake. If doing bad things to me requires
> breaking in to my individual home, that's fine. If it is merely much
> less likely that I lose my data rather than certain that I have no
> backup at all, that's fine.
>
> BTW, automation *does* do a good job of making such things invisible.
> I haven't lost any real data since I started using Time Machine from
> Apple, and I have non-technical friends who use it and are totally
> happy with the results. I wish there was an automated thing in Time
> Machine to let me trade backups with an offsite friend as well.
The Least-Authority Filesystem comes with a nice backup tool ("tahoe backup"),
but it does not come with a nice GUI for your non-technical friends.
Regards,
Zooko
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography