For now my server doesn’t have very important data most of it are your “Linux isos” I can just download again and I’m thinking of starting to move my file and photos to the server but in afraid. What if I get a ransomwarei don’t realize and all my backups get encrypted too? Or if the backups are corrupted and my disks breaks? But also I’m afraid about cloud because I’ve seen some posts about people getting their google accounts closed without notice for breaking TOS (maybe they did something wrong maybe not).

  • hadrabap@alien.topB
    link
    fedilink
    English
    arrow-up
    4
    ·
    7 months ago

    I’m more scared of online services being discontinued and/or being getting vendor locked and forced to pay ransom on a regular basis. Therefore, I host and back up everything on my own.

  • Malossi167@alien.topB
    link
    fedilink
    English
    arrow-up
    4
    ·
    7 months ago

    It is impossible to fully eliminate the risk but with a decent backup system in place it is somewhat unlikely to lose all of your data.

    The 321rule should be used as a baseline. Your local backup should be snapshotted and somewhat hardened against ransomware (pull backups instead of pushing them, do not mount the backup volume to other machines). Cold backups also help.

    Can I construct scenarios in which I lose all my stuff? Sure. But in those, we are either in deep shit anyway (CME, some big astroid) or it is pretty unlikely (targeted hacking)

    • gargravarr2112@alien.topB
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 months ago

      This. With a proper backup strategy, you are reducing the probability of a catastrophic sequence of events. It becomes P(some unlikely event) x P(some other unlikely event) x … Etc. for as many events you can think of and/or can afford to mitigate.

      As you say, the risk will never be zero. And even the best-laid plans can fail - the Gitlab incident a few years back saw five layers of backups and disaster preparedness fail.

      Really, all you can do is backup your data using standard methods, and TEST THE RESTORE before you need to rely on it!

      • Malossi167@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 months ago

        My backups are tiered. Some stuff gets no backup at all, some gets even more than 3.And I tend to reuse HDDs that got replaced in my main machine due to size for my backups. Power consumption hardly matters when it only runs for a few minutes a day.

      • mirokra@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 months ago

        How much value does the data have for you?

        If it’s of very low value, that it doesn’t even justify the costs of doing proper backups, then it’s not so important to worry about it either.

  • bobj33@alien.topB
    link
    fedilink
    English
    arrow-up
    3
    ·
    7 months ago

    Aren’t you scared about loosing your data?

    No. I still have files from 1991. I’ve got files that have migrated from floppy disk to hard drive to QIC-80 tape to PD (Phase Change) optical disk to CD-RW to DVD+RW and now back to hard drives.

    What if I get a ransomwarei don’t realize and all my backups get encrypted too?

    Then you need to detect the ransomware before you backup. I use rsync --dry-run and look at what WOULD change before I run it for real. If I see thousands of files change that I did not expect then I would not run the backup and investigate what changed before running the rsync command for real.

    Or if the backups are corrupted

    I have 3 copies of my data. Local file server, local backup, remote file server.

    I also run rsnapshot on /home every hour to another drive in the machine. I also run snapraid sync to dual parity drives in the system once a day.

    I generate and compare stored file checksums twice a year across all 3 copies to detect any corruption. Over 300TB I have about 1 failed checksum every 2 years.

    and my disks breaks?

    If one of my disks breaks I buy a new one and restore from backups.

    But also I’m afraid about cloud

    I don’t use any cloud services because I don’t trust them.

    • gerardit04@alien.topOPB
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      7 months ago

      About rsync --dry-run, let’s say I got a ransonware but its till encrypting the data will it detect the changes?

  • Treczoks
    link
    fedilink
    English
    arrow-up
    3
    ·
    7 months ago

    A) Make backups B) take them offline.

  • he-tried-his-best@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    Only thing dear to me is my family photos and videos over the years. They’re backed up to two different cloud providers. Everything else is ultimately downloadable.

  • kring1@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    Paranoia is the reason I self host. Clouds can kick you out or lose your data at any time.

  • shrugal
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    7 months ago

    The key is to do regular backups to a different location, and to keep previous versions as read-only backups for a certain timespan. If something happens to the local data you can just restore from the remote backup, and also pick an unmodified previous version in case of a ransomware attack.

    E.g. I do a daily encrypted cloud backup of everything that can’t just be downloaded again, and the backup provider keeps previous versions for 30 days.

  • sloppy_diffuser@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    I backup to Backblaze b2. I encrypt myself using rclone. Costing me $1-2/mo for about 100Gb that I’m currently using.

    API key I use for automated backups is pretty much limited to write only and files are set to hidden when deleted, so not much risk, just an annoyance, if the key were stolen and they defaced my backups.

    Once a year I might go delete some history to reduce my usage.

    I lean towards scripts to automate setting up a system, so I don’t do full system backups. Downloaded video I also mostly skip using mirrored storage. In the event of a real disaster, its an acceptable loss.

  • brando2131@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    ZFS (mirrored) two HDDs. If one HDD fails, then replace it and let it rebuild. Use 3 HDDs mirrored if you really think you could get a failure while the array is rebuilding.

    Also have two external backups, one you do regularly at home, and another you keep off-site. When you visit that location (be it your parents, siblings, relatives, friends house) swap out your external backup with their off-site to ensure its kept up to date.

    Make sure all disks are fully encrypted of course.

  • EspritFort@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    For now my server doesn’t have very important data most of it are your “Linux isos” I can just download again and I’m thinking of starting to move my file and photos to the server but in afraid. What if I get a ransomwarei don’t realize and all my backups get encrypted too? Or if the backups are corrupted and my disks breaks? But also I’m afraid about cloud because I’ve seen some posts about people getting their google accounts closed without notice for breaking TOS (maybe they did something wrong maybe not).

    What you’re describing sounds like general anxiety. So if you’re asking whether I’m suffering from anxiety, then no :P There are risks in life and precautions you can take against them. I’m just as “scared” about losing data as I am about getting run over by a car, that is to say not at all. Both scenarios are horrible, both can be reduced in risk by employing reasonable countermeasures and behaviors. Beyond that it’s out of my control so there’s no point in worrying.

    The only hazy variable in this kind of contemplation is: Am I knowledgeable enough to properly gauge the risks and know the “reasonable countermeasures”? And if you’re asking “Do you know enough?” or “Do you spend enough time learning new things?” then my answer would always be an emphatic “No!” because there’s no such thing as enough knowledge and competence.

  • Tiwenty@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    I used to regularly backup my photos to an external drive, but it’d still be in my house. Recently I just opened a cold object storage bucket at OVH and rclone to it every night. So even if they fail, the chance they fail at the same time as I do is pretty minimal. And I pay like 0.75€ a month for ~400GB

  • Plane_Resolution7133@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    Some data are backed up to a local NAS, some of that data is backed up to cloud (not Google or the big ones).

    Most of my data aren’t important. Photo library is both local, in the cloud, and most on offsite DVDs.

    ~45K lossless music files is local and cloud. Those would suck losing, but I could rip them again.

    I’ve been considering tape backup again, it’s like 20 years since I used it at home.

  • ice-h2o@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    Have multiple copies of the data. Use snapshots, they don’t get encrypted by a ransomware because they are read only and can’t be accessed via samba or nfs. It’s only a problem when the attacker gets root access to your NAS. Use a cloud provider like backblaze and backup your data encrypted. If you are really scared that ransomeware data will overwrite your backups use 3-2-1 and Grandfather-father-son backup strategy. But all this comes at a cost.

  • speaksoftly_bigstick@alien.topB
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    Not as many years ago as I would prefer given my professional experience, I was running a lot from home. Most of it for myself to learn more (so nothing my home itself was dependent on) but a percentage of it was for storage of pictures, home videos, digitalized documents, emails, etc.

    I ran my own exchange server for years (utilizing my own TLD that I bought in 2008).

    I was in the process of migrating data from a couple of older hosts to the newer ones I had setup in the garage; basically from two cobbled together Dell T series poweredge servers in my hall closet to a small stack of R series poweredge in a 42u cabinet rack in the garage.

    My whole stack was setup across the two hosts including backups from veeam from one to the other and copies.ofnthe backups stored on an external. Due to the size of the backups and where I was on my life financially, anything hosted up in cloud space was just a little out of my budget. Anything I could afford was suspicious at the time.

    This too long story ends basically by me not paying attention to what I was doing and ended up destroying the raid on both of the original hosts without having finished moving all my data.

    I lost years of emails from my exchange server, all the pictures and home made videos of my daughters life from birth to that point in time, and my backup data.

    All from my own mistake(s).

    I did everything I was “supposed” to do to keep stuff protected until I messed it up.

    My daughter passed away this year in February at 16 years old. I’d give anything to have those pictures and videos back.

    My point is, you can plan and execute and throw money at it if you’re able. And you’ll likely be fortunate enough to never really lose anything that’s valuable to you. But even planning and implementing, you can still lose stuff just by oversight and human error.

    That’s the game, man. 🤷

    • anturk@alien.topB
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 months ago

      I also have been there kinda when i was about 16 years old i guess such a big lesson for me now if i do some extra backups and al kinda backups and shit my friends think i am paranoid.

      Well yes i am because i have been there

      • ManSpeaksInMic@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 months ago

        As the saying goes: That you’re paranoid does not mean they’re not out to get you … 😃

        I have those battle scars too. :(

    • gerardit04@alien.topOPB
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 months ago

      I’m sorry for your loss. Thats the type of scenario I fear about, I can have the 321 backup but errors happen like not configuring you backup correctly, or destroying the raid… also I dont have a lot of money to buy drives and most of them are refurbished and I dont know if I can trust them.

      • adamshand@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 months ago

        The thing is, these sorts of losses aren’t limited to selfhosting. Selfhosting introduces some new risks and reduces some other risks.

        Digital data is inherently fragile. It takes active work to preserve it.

        That’s one of the reasons my wife and I make an actual physical photo book each year of our favourite photos.