Microsoft

After Failure to Detect Major Breaches, US Mulls Real-Time Threat Sharing with Private Sector (msn.com) 67

America is contemplating how to respond to breaches "pulled off by Russia and China against a broad array of government and industrial targets," reports the New York Times: Both hacks exploited the same gaping vulnerability in the existing system: They were launched from inside the United States — on servers run by Amazon, GoDaddy and smaller domestic providers — putting them out of reach of the early warning system run by the National Security Agency. The agency, like the C.I.A. and other American intelligence agencies, is prohibited by law from conducting surveillance inside the United States, to protect the privacy of American citizens. But the F.B.I. and Department of Homeland Security — the two agencies that can legally operate inside the United States — were also blind to what happened, raising additional concerns about the nation's capacity to defend itself from both rival governments and nonstate attackers like criminal and terrorist groups. In the end, the hacks were detected long after they had begun not by any government agency but by private computer security firms...

Biden administration officials said they would seek a deeper partnership with the private sector, tapping the knowledge of emerging hacking threats gathered by technology companies and cybersecurity firms. The hope, current and former officials say, is to set up a real-time threat sharing arrangement, whereby private companies would send threat data to a central repository where the government could pair it with intelligence from the National Security Agency, the C.I.A. and other spy shops, to provide a far earlier warning than is possible today.

A U.S. representative who co-chairs a cyberspace commission colorfully characterized both breaches to the TImes. "When not one but two cyberhacks have gone undetected by the federal government in such a short period of time, it's hard to say that we don't have a problem. The system is blinking red."

But then there's this: Last month, in the days before Microsoft released an emergency patch for vulnerable Exchange Servers, multiple state-backed Chinese groups were apparently tipped off that the company was testing a patch. They began gorging on vulnerable systems with a speed and aggression that some security experts said they had never seen before.

It is unclear how exactly these Chinese groups learned of Microsoft's patch, but the timing suggests they caught wind of the moves when Microsoft rolled out a test version of its patch to its security partners at cybersecurity firms in late February. Eighty companies participate in a longstanding partnership with Microsoft, known as the Microsoft Active Protections Program, including 10 Chinese firms. Microsoft confidentially alerts these companies to emerging cyberthreats and vulnerabilities ahead of its official patch cycle. The company is investigating whether one of its partners may have leaked to Chinese hackers or was itself hacked.

Programming

After 20 Years, Have We Achieved the Vision of the Agile Manifesto? (zdnet.com) 205

"We are uncovering better ways of developing software by doing it and helping others do it," declared the Agile Manifesto, nearly 20 years ago. "Through this work we have come to value..."

* Individuals and interactions over processes and tools
* Working software over comprehensive documentation
* Customer collaboration over contract negotiation
* Responding to change over following a plan

Today a new ZDNet article asks how far the tech industry has come in achieving the vision of its 12 principles — and why Agile is often "still just a buzzword." The challenge arises "because many come to agile as a solution or prescription, rather than starting with the philosophy that the Agile Manifesto focused on," says Bob Ritchie, VP of Software at SAIC. "Many best practices such as automated test-driven development, automated builds, deployments, and rapid feedback loops are prevalent in the industry. However, they are frequently still unmoored from the business and mission objectives due to that failure to start with why."

Still, others feel we're still nowhere near achieving the vision of the original Agile Manifesto. "Absolutely not at a large scale across enterprises," , says Brian Dawson, DevOps evangelist with CloudBees. "We are closer and more aware, but we are turning a tanker and it is slow and incremental. In start-ups, we are seeing much more of this; that is promising because they are the enterprises of the future." Agile initiatives "all too often are rolled out from, and limited to, project planning or the project management office. To support agile and DevOps transformation, agile needs to be implemented with all stakeholders."

Some organizations turn to agile "as a panacea to increase margins by cutting cost with a better, shinier development process," Ritchie cautions. "Others go even further by weaponizing popular metrics associated with agile capacity planning such as velocity and misclassifying it as a performance metric for an individual or team. In these circumstances, the promises of the manifesto are almost certainly missed as opportunities to engage and collaborate give way to finger pointing, blame, and burnout." What's missing from many agile initiatives is "ways to manage what you do based on value and outcomes, rather than on measuring effort and tasks," says Morris. "We've seen the rise of formulaic 'enterprise agile' frameworks that try to help you to manage teams in a top-down way, in ways that are based on everything on the right of the values of the Agile Manifesto. The manifesto says we value 'responding to change over following a plan,' but these frameworks give you a formula for managing plans that don't really encourage you to respond to change once you get going."

IT

More San Francisco Tech Companies Cancel Leases Due to Remote Work (sfgate.com) 79

Salesforce canceled its 325,000-square-foot lease at the unbuilt Parcel F tower in San Francisco's Transbay neighborhood, reports SFGate: The company announced in February that more than half of its workforce will continue working remotely or on a flexible schedule after the pandemic is over...

The lease termination is just the latest blow to San Francisco's downtown office footprint as more companies shrink or offload leases because of the persistence of remote work. The lease on Yelp's 161,876-square-foot office space at 140 New Montgomery St. is up in October 2021 and the entire space has been listed for rent. WeWork confirmed it would be scaling back its Bay Area locations and is closing five downtown locations. Just this week, the Mission Bay headquarters once leased by Dropbox is being sold for $1.08 billion. The company adopted a remote work policy in October 2020... In August 2020, Pinterest paid $89.5 million to terminate its lease for 88 Bluxome.

Crime

Encrypted Messaging Service Cracked by Belgian Police, Followed by Dozens of Arrests (brusselstimes.com) 92

"The cracking of a previously-unbreakable encrypted messaging service popular with criminals involved in drug trafficking and organised crime delivered a major victory for the justice system on Tuesday," writes the Brussels Times, in a story shared by DI4BL0S: The cracking of the expensive messaging app, called "Sky ECC," was what allowed over 1,500 police officers across Belgium to be simultaneously deployed in at least 200 raids, many of which were centred around Antwerp and involved special forces. Investigators succeeded in cracking Sky ECC at the end of last year, according to reporting by De Standaard, and as a result were able to sort through thousands of messages major criminals were sending each other over the course of a month. Information gained from those conversations is what led to Tuesday's historic operation, two years in the making.

Sky ECC became popular with drug criminals after its successor Encrochat was cracked in 2020 by French and Dutch investigators, who were able to intercept over 100 million messages sent via the app. That led to over a hundred suspects being arrested in the Netherlands, uncovering a network of laboratories where crystal meth and other drugs were being produced and allowing police to seize 8,000 kilos of cocaine and almost €20 million....

In a press conference by Belgium's federal public prosector's office on Tuesday afternoon, authorities stated that 17 tonnes of cocaine and €1.2 million were seized, and that 48 suspects were arrested.

Critics of Sky ECC "say more than 90% of its customers are criminals," according to the Brussels Times. Days later America's Justice Department indicted the CEO of Sky Global "for allegedly selling their devices to help international drug traffickers avoid law enforcement," reports Vice. They call it "only the second time the DOJ has filed charges against an encrypted phone company, and signals that the DOJ will continue to prosecute the heads and associates of companies that they say cater deliberately to facilitating criminal acts."

Earlier the Brussels Times had quoted the app's makers statement that they "strongly believe that privacy is a fundamental human right."

The newspaper also reported that Sky ECC calls itself "the world's most secure messaging app" — and "had previously said 'hacking is impossible'" — though in fact investigators have already decrypted almost half a billion messages.
Security

Attacks Leveraging Microsoft Exchange Vulnerabilities 'Have Escalated', Doubling Every Three Hours (cnn.com) 43

Attacks that leverage Microsoft Exchange vulnerabilities "have escalated," warns CNN. They cite a senior White House official saying the window for updating exposed servers is incredibly short -- "measured in hours, not days." On Thursday, Microsoft and security researchers warned that the vulnerabilities are now being combined with another potent cybersecurity threat: ransomware, which locks up a computer or a network's files and holds them hostage until the victim pays a fee. "We have detected and are now blocking a new family of ransomware being used after an initial compromise of unpatched on-premises Exchange Servers," Microsoft said in a tweet.

Security experts at Palo Alto Networks estimated Thursday that at least 20,000 US-based Exchange servers remain unpatched and vulnerable to exploitation, and as many as 80,000 around the globe.

Other security researchers say the pace of attacks against Exchange servers is rising as opportunistic hackers seek to take advantage of the opening found by Hafnium, the group Microsoft has said is responsible for the original breaches and is "assessed to be state-sponsored and operating out of China." The number of attempted attacks against organizations has been doubling every two to three hours, according to Check Point Research, which monitors the internet for malicious activity.

Bug

Three Flaws in the Linux Kernel Since 2006 Could Grant Root Privileges (scmagazine.com) 94

"Three recently unearthed vulnerabilities in the Linux kernel, located in the iSCSI module used for accessing shared data storage facilities, could allow root privileges to anyone with a user account," reports SC Media: "If you already had execution on a box, either because you have a user account on the machine, or you've compromised some service that doesn't have repaired permissions, you can do whatever you want basically," said Adam Nichols, principal of the Software Security practice at GRIMM. While the vulnerabilities "are in code that is not remotely accessible, so this isn't like a remote exploit," said Nichols, they are still troublesome. They take "any existing threat that might be there. It just makes it that much worse," he explained. "And if you have users on the system that you don't really trust with root access it, it breaks them as well."

Referring to the theory that 'many eyes make all bugs shallow,' Linux code "is not getting many eyes or the eyes are looking at it and saying that seems fine," said Nichols. "But, [the bugs] have been in there since the code was first written, and they haven't really changed over the last 15 years...." That the flaws slipped detection for so long has a lot to do with the sprawl of the the Linux kernel. It "has gotten so big" and "there's so much code there," said Nichols. "The real strategy is make sure you're loading as little code as possible."

The bugs are in all Linux distributions, Nichols said, although the kernel driver is not loaded by default. Whether a normal user can load the vulnerable kernel module varies. They can, for instance, on all Red Hat based distros that GRIMM tested, he said. "Even though it's not loaded by default, you can get it loaded and then of course you can exploit it without any trouble...."

The bugs have been patched in the following kernel releases: 5.11.4, 5.10.21, 5.4.103, 4.19.179, 4.14.224, 4.9.260, and 4.4.260. All older kernels are end-of- life and will not receive patches.

Microsoft

Microsoft Probing Whether Leak Played Role in Suspected Chinese Hack (wsj.com) 16

Microsoft is investigating whether a world-wide cyberattack on tens of thousands of its corporate customers may be linked to a leak of information by the company or its partners, WSJ reported Friday, citing people familiar with the matter. From a report: The investigation centers in part on the question of how a stealthy attack that began in early January picked up steam in the week before the company was able to send a software fix to customers. In that time, a handful of China-linked hacking groups obtained the tools that allowed them to launch wide-ranging cyberattacks that have now infected computers all over the world running Microsoft's Exchange email software. Some of the tools used in the second wave of the attack, which is believed to have begun Feb. 28, bear similarities to "proof-of-concept" attack code that Microsoft distributed to antivirus companies and other security partners Feb. 23, investigators at security companies say. Microsoft had planned to release its security fixes two weeks later, on March 9, but after the second wave began it pushed out the patches a week early, on March 2, according to researchers.
Security

Swiss Police Raid Apartment of Verkada Hacker, Seize Devices (bloomberg.com) 24

Swiss authorities raided the apartment Friday of a hacker who claimed credit for breaching the Silicon Valley security camera company Verkada and gaining access to its customers' surveillance feeds, according to the hacker and a search warrant seen by Bloomberg News. From the report: Tillie Kottmann said their apartment in Lucerne, Switzerland, was raided and that police seized the hacker's electronic devices. The warrant was based on an alleged hack that took place last year and not on the recent breach of Verkada. After being notified of the breach by Bloomberg News, Verkada referred the matter to the FBI. The breach exposed live camera feeds of companies like Tesla, as well as hospitals, jails, and schools. According to a copy of the search warrant provided to Bloomberg News, the search was conducted as part of a U.S criminal case against Kottmann in the Western District of Washington. The warrant requested documents related to hacking as well as information on cryptocurrency holdings. Kottmann has been accused of unauthorized access to protected computers, identify theft, and fraud.
Chrome

Chrome 89 Increases Desktop Memory Efficiency With PartitionAlloc (arstechnica.com) 61

Google Chrome version 89 began rolling out to users in the stable channel on March 2 and should be on most people's machines by now. From a report: The new build offers significant memory savings on 64-bit Windows platforms thanks to increased use of Google's PartitionAlloc memory allocator. On macOS, Chrome 89 plays catch-up and gets closer to the performance of the flagship Windows builds. Google says use of RAM in 64-bit Windows is down up to 22 percent in the browser process, 8 percent in the renderer, and 3 percent in the GPU. The company also claims a 9 percent decrease in latency, meaning a more responsive browser. The improvements are largely due to intercepting malloc() calls with PartitionAlloc. Chrome 89 has also gotten significantly more aggressive about discarding unused RAM. When you scroll resources such as large images off-screen in the foreground tab, Chrome discards the memory those resources used. The change impacts background tabs as well, resulting in a savings of as much as 100MiB per tab.
Microsoft

Up To 60,000 Computer Systems Exposed In Germany To Microsoft Flaw (reuters.com) 14

As many as 60,000 computer systems in Germany were exposed to a flaw that allows unauthorized users to access systems in Microsoft's email software, the head of its cybersecurity watchdog said on Wednesday. Reuters reports: More than half of the vulnerabilities were addressed following a warning last weekend by the Federal Office for Information Security (BSI), but around 25,000 systems still need to be fixed, BSI chief Arne Schoenbohm said. "The warning has worked. In Germany, many Exchange servers have been secured by downloading patches," Schoenbohm said in written comments to Reuters. "Every vulnerable system is one too many and can lead to harm."

In a 14-page report on the Microsoft vulnerability, the BSI said the behavior of hackers exploiting it had changed sharply since it was publicly revealed. Initially, most targets had been think tanks, universities, non-governmental organizations, law firms and defense companies - mostly in the United States. "Now, these exploits are being deployed at mass scale against thousands of targets - apparently worldwide," the report said. At least 10 different hacking groups were using the latest flaw in Microsoft's mail server software to break into targets around the world, according to researchers at cybersecurity company ESET. In Germany, two federal authorities have been affected by the hack, the BSI said, declining to say which.

Privacy

Hackers Breach Thousands of Security Cameras, Exposing Tesla, Jails, Hospitals (bloomberg.com) 53

New submitter ekeko writes: A group of hackers say they breached a massive trove of security-camera data collected by Silicon Valley startup Verkada, gaining access to live feeds of 150,000 surveillance cameras inside hospitals, companies, police departments, prisons and schools. Companies whose footage was exposed include carmaker Tesla and software provider Cloudflare. In addition, hackers were able to view video from inside women's health clinics, psychiatric hospitals and the offices of Verkada itself. Some of the cameras, including in hospitals, use facial-recognition technology to identify and categorize people captured on the footage. The hackers say they also have access to the full video archive of all Verkada customers. In a video seen by Bloomberg, a Verkada camera inside Florida hospital Halifax Health showed what appeared to be eight hospital staffers tackling a man and pinning him to a bed. Halifax Health is featured on Verkada's public-facing website in a case study entitled: "How a Florida Healthcare Provider Easily Updated and Deployed a Scalable HIPAA Compliant Security System." A spokesman for Halifax confirmed Wednesday that it uses Verkada cameras but added that "we believe the scope of the situation is limited."
Security

Linux Foundation Debuts Sigstore Project for Software Signing (darkreading.com) 19

The Linux Foundation has announced the launch of Sigstore, a new nonprofit initiative that aims to improve open source software supply chain security by making it easier for developers to adopt cryptographic signing for different components of the software development process. From a report: Sigstore will be free for software providers and developers, who can use it to securely sign software artifacts such as release files, container images, binaries, and bill-of-material manifests. Signing materials are then stored in a tamper-proof public log. The service's code and operation tooling will be fully open source and maintained and developed by the Sigstore community. Founding members include Red Hat, Google, and Purdue University. The idea for the service came from Luke Hinds, security engineering lead in Red Hat's Office of the CTO. He pitched the concept to Google software engineer Dan Lorenc, and the two began to work on it. Now the Sigstore project has a "small but agile community" working on its development, Lorenc says.
Data Storage

Dropbox To Acquire Secure Document Sharing Startup DocSend for $165M (techcrunch.com) 9

Dropbox announced today that it plans to acquire DocSend for $165 million. The company helps customers share and track documents by sending a secure link instead of an attachment. From a report: "We're announcing that we're acquiring DocSend to help us deliver an even broader set of tools for remote work, and DocSend helps customers securely manage and share their business critical documents, backed by powerful engagement analytics," Houston told me. When combined with the electronic signature capability of HelloSign, which Dropbox acquired in 2019, the acquisition gives the company an end-to-end document sharing workflow it had been missing. "Dropbox, DocSend and HelloSign will be able to offer a full suite of self-serve products to help our millions of customers manage the entire critical document workflows and give more control over all aspects of that," Houston explained.
Privacy

A Bug in a Popular iPhone App Exposed Thousands of Call Recordings (techcrunch.com) 33

A security vulnerability in a popular iPhone call recording app exposed thousands of users' recorded conversations. From a report: The flaw was discovered by Anand Prakash, a security researcher and founder of PingSafe AI, who found that the aptly named Call Recorder app allowed anyone to access the call recordings from other users -- by knowing their phone number. But using a readily available proxy tool like Burp Suite, Prakash could view and modify the network traffic going in and out of the app. That meant he could replace his phone number registered with the app with the phone number of another app user, and access their recordings on his phone. TechCrunch verified Prakash's findings using a spare phone with a dedicated account. The app stores its user's call recordings on a cloud storage bucket hosted on Amazon Web Services. Although the public was open and lists the files inside, the files could not be accessed or downloaded. The bucket was closed by press time.
Microsoft

European Banking Regulator EBA Targeted In Microsoft Hacking (reuters.com) 4

An anonymous reader quotes a report from Reuters: The European Banking Authority on Monday said it had been targeted by hackers, although no data had been obtained and it was redoubling efforts to shield itself amid a global cyber attack exploiting flaws in Microsoft's mail server software. The European Union's banking regulator, which gathers and stores swathes of sensitive data about banks and their lending, said it believed the cyber attack had struck only its email servers. It is the latest prominent victim among tens of thousands of organizations in Asia and Europe targeted in a campaign which Microsoft Corp says makes use of previously undetected vulnerabilities in different versions of its mail server software. The hacks are continuing despite emergency patches issued by Microsoft, which has said it is working with government agencies and security companies to help customers. However, one scan of connected devices showed only 10% of those vulnerable had installed the patches by Friday, though the number was rising.
Privacy

Cellebrite Hacking Tools Sold To Bangladesh Police Unit Known For Human Rights Abuses (aljazeera.com) 57

An anonymous reader quotes a report from Al Jazeera: Documents obtained by Al Jazeera's Investigative Unit (I-Unit) and Israeli newspaper Haaretz reveal how the Bangladesh government spent at least $330,000 on phone-hacking equipment made by an Israeli company, even though the two countries do not have diplomatic relations. Developed by the Cellebrite security firm, UFED is a product that is capable of accessing and extracting data from a wide range of mobile phones. Its ability to hack encrypted phone data has worried civil rights campaigners, who have long called for its use to be more strictly regulated. It is unclear whether UFED was provided to Bangladesh directly by the Israeli company or via a Cellebrite subsidiary based elsewhere in the world, presumably with the intention to mask its origins.

The latest documents obtained by I-Unit, which Al Jazeera also found on the Bangladesh home ministry's own website, relate to contracts signed in 2018 and 2019. They are from the Public Security Division, a department in the Ministry of Home Affairs that is in charge of domestic security and whose agencies include the Bangladesh police force and border guards. The paperwork details how nine officers from the country's Criminal Investigations Department were given the approval to travel to Singapore in February 2019 to receive training on UFED to allow them to unlock and extract data from mobile phones. It outlines how the Bangladeshi staff would ultimately qualify as Cellebrite Certified Operators and Cellebrite Certified Physical Analysts.

The documents also say the Rapid Action Battalion (RAB), a paramilitary force that has a well-documented record of abductions, torture and disappearances, would be trained on the usage of Cellebrite's hacking systems under an ongoing project that began in 2019 and is set to be completed in June 2021. The latest revelation that Bangladesh security services are being equipped with highly intrusive devices capable of accessing encrypted phones that contain private messages comes amid growing concerns over the country's human rights record.

Encryption

DARPA Taps Intel To Help Build the Holy Grail of Encryption (techrepublic.com) 54

The Defense Advanced Research Projects Agency, or DARPA, has signed an agreement with Intel to add it to its Data Protection in Virtual Environments project, which aims to create a practically useful form of fully homomorphic encryption. From a report: Fully homomorphic encryption has been described as the "holy grail" of encryption because it allows encrypted data to be used without ever having to decrypt it. Fully homomorphic encryption isn't fantasy -- it already exists and is usable, but it is incredibly impractical. "FHE adoption in the industry has been slow because processing data using fully homomorphic encryption methods on cryptograms is data intensive and incurs a huge 'performance tax' even for simple operations," Intel said in a press release.

The potential benefits of fully homomorphic encryption make creating a practical way to use it a cybersecurity imperative. Intel succinctly describes the biggest problem in data security as being caused by "encryption techniques [that] require that data be decrypted for processing. It is during this decrypted state that data can become more vulnerable for misuse." The goal of the Data Protection in Virtual Environments program is to develop an accelerator for fully homomorphic encryption that will make it more practical and scalable, which is where Intel comes in. The chip manufacturer's role in the project will be academic research and the development of an application-specific integrated circuit that will accelerate fully homomorphic encryption processing. Intel said that, when fully realized, its accelerator chip could reduce processing times by five orders of magnitude over existing CPU-driven fully homomorphic encryption systems.

Intel

Intel's Thunderbolt Pushes Into Mainstream as Fast Alternative To USB (cnet.com) 193

Thunderbolt, Intel's super-speedy connection technology, isn't widely used. But that may change in the coming year, as more computer makers incorporate the USB competitor into their new models. From a report: Intel has hoped Thunderbolt, which debuted in 2011 on Apple's 2011 MacBook Pro, would become commonplace for computer users. A year later, the chipmaker forecast that "most PCs" would have Thunderbolt by 2015 to 2017. Despite the hype, only premium PCs carry the fast connection. To get a boost in adoption, Intel has built Thunderbolt into its newest Core processors, code-named Tiger Lake, which means laptop makers get Thunderbolt without having to pay extra for separate controller chips. Because Intel chips are so widely used, the company says Thunderbolt will now have its moment to shine.

"I would expect by 2022 Thunderbolt will be in more than 50% of the PCs sold," said Jason Ziller, who runs Intel's connectivity products, adding that more than half of laptops that ship in the next year will "definitely" carry the technology. Ziller has led Thunderbolt work since before it debuted in Apple's 2011 MacBook Pro laptops almost exactly 10 years ago. PC ports don't capture the imagination the way fast processors or smartphone cameras do. But they're a crucial part of most people's computing experience. Thunderbolt ports provide fast and versatile connections to external storage devices, monitors, network adapters and other peripherals. They can replace ports for HDMI, DisplayPort, Ethernet and power. The new Thunderbolt 4 lets multiport docks and hubs offer three Thunderbolt ports instead of just one.

China

Preparing for Retaliation Against Russia, US Confronts Hacking by China (nytimes.com) 126

The proliferation of cyberattacks by rivals is presenting a challenge to the Biden administration as it seeks to deter intrusions on government and corporate systems. From a report: Just as it plans to begin retaliating against Russia for the large-scale hacking of American government agencies and corporations discovered late last year, the Biden administration faces a new cyberattack that raises the question of whether it will have to strike back at another major adversary: China. Taken together, the responses will start to define how President Biden fashions his new administration's response to escalating cyberconflict and whether he can find a way to impose a steeper penalty on rivals who regularly exploit vulnerabilities in government and corporate defenses to spy, steal information and potentially damage critical components of the nation's infrastructure. The first major move is expected over the next three weeks, officials said, with a series of clandestine actions across Russian networks that are intended to be evident to President Vladimir V. Putin and his intelligence services and military but not to the wider world.

The officials said the actions would be combined with some kind of economic sanctions -- though there are few truly effective sanctions left to impose -- and an executive order from Mr. Biden to accelerate the hardening of federal government networks after the Russian hacking, which went undetected for months until it was discovered by a private cybersecurity firm. The issue has taken on added urgency at the White House, the Pentagon and the intelligence agencies in recent days after the public exposure of a major breach in Microsoft email systems used by small businesses, local governments and, by some accounts, key military contractors. Microsoft identified the intruders as a state-sponsored Chinese group and moved quickly to issue a patch to allow users of its software to close off the vulnerability. But that touched off a race between those responsible for patching the systems and a raft of new attackers -- including multiple other Chinese hacking groups, according to Microsoft -- who started using the same exploit this week.

Cloud

Ask Slashdot: What Do You Use for Backups at Home? 283

"I am curious as to what other Slashdotters use for backing up of home machines," asks long-time Slashdot reader serviscope_minor: I moved away from the "bunch of disks with some off site" method. I found most of the methods generally had one or more of the following problems: poor Linux support, weak security (e.g. leaking file names), outrageously expensive, hard to set up, tied to a single storage supplier I don't fully trust, entirely proprietary (which makes me doubt long term stability), lack of file history, reputation for slowness, and so on.

My current solution is Unixy: separate tools for separate jobs. Borg for backups to a local machine. Rclone for uploading to business cloud storage, versioned cloud storage to provide resistance against bitrot and other corruption.

They're interested in "what other Slashdotters use," as well as "why and what your experience has been given more than superficial testing." So share you own thoughts in the comments.

What do you use for backups at home?

Slashdot Top Deals