this post was submitted on 05 Apr 2024
70 points (97.3% liked)
Asklemmy
43856 readers
1606 users here now
A loosely moderated place to ask open-ended questions
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- [email protected]: a community for finding communities
~Icon~ ~by~ ~@Double_[email protected]~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
People say RAID isn't backup, but I've never understood that. Yes it's only one medium and it's probably not off-site, but if you've got an off-site copy in a different medium, why doesn't a single RAID 5 count as 2 copies of your data to add up to get the 3 in 321 backup?
Media failure isn't the only reason to back up. If you delete a file on a RAID array, it's gone on all disks. If you need to recover that deleted file, you can't recover from RAID. The same goes for formatting/damage of the file system, recovery from something wrong inside a database, etc.
Suppose you’re hit by a ransomware attack and all the data on your NAS gets encrypted. Your RAID “backup” is just as inaccessible as everything else. So it’s not a backup. A true backup would let you recover from the ransomware attack once you have identified and removed the malware that allowed the attack.
I really, really liked @[email protected]'s answer, because even as I was reading it, I was thinking of things that they could have said—but didn't—which would have been easily rebutted. Those things fell into two basic categories: malware, and environmental effects.
As I understand it, malware is an issue with any online backup system, whether that's a RAID or just a second external hard drive. So I don't really think it works as an answer to why RAIDs specifically don't qualify as backup.
A well thought out and implemented backup system, along with a good security setup is how you deal with malware. If backups won’t protect you from malware then you’re doing backups wrong. A proper backup implementation keeps a series of full backups plus incremental backups based on those full ones. So say your data doesn’t change very often, then you might do a full backup once a month and incremental ones twice a week. You keep 6 months of the combinations of full & incrementals, you don’t just overwrite the backups with new ones.
If you’re doing backups like that and you suffer a malware attack then you have the ability to recover data as far as 6 months ago. The chances you don’t discover malware encrypting your data for 6+ months is tiny. If you’re really paranoid then you also test recovering files from random backups on a regular basis.
My employer has detected and blocked multiple malware attacks using a combination of the above practices plus device management software that can detect unusual NAS activity and block suspect devices on our networks. Each time our security team was able to identify the encrypted files and restore over 99% from backups.
RAID is resiliency, but not a backup. It doesnt hold a previous dates version, it doesn't protect against accidental deletion. Nor does it protect against changes to files.
Many causes of data loss affect all RAID drives equally from accidental deletion over power surges, fire, water damage, theft,....
I really, really liked @[email protected]'s answer, because even as I was reading it, I was thinking of things that they could have said—but didn't—which would have been easily rebutted. Those things fell into two basic categories: malware, and environmental effects.
Environmental effects like water damage and theft are a problem for any local storage, regardless of the technology. If it's a RAID, or an external USB drive, or even a NAS in your closet. The power surge is probably the best example of RAID not being backup, since it's very possible that one device might receive the surge but not the other, if they're connected to different outlets. But as for the other ones? Eh, I don't really buy it.
I have literally lost all data on a RAID6 of 12 drives since the power distributor in the server (the bit between the redundant PSUs and the rest of the system) got fried and took 5 out of the 12 drives with it.
What if the RAID 5 gets encrypted with ransomware, how many backups are there?