On 11/11/2011 09:22 PM, Grant wrote: > > So if I push, I don't really have backups because anyone who breaks > into the backed-up system can delete all of its backups like this: > > rdiff-backup --remove-older-than 1s backup@12.34.56.78::/path/to/backup > > And if I pull, none of my backed-up systems are secure because anyone > who breaks into the backup server has root read privileges on every > backed-up system and will thereby "gain full root privileges quickly." >
It's a false dichotomy[1], but sums up the trade-off between those two options well enough. The last "hacker" who tried to delete everything on my system was a 5.25in floppy. So, I'm biased towards the other case. [1] Third option: choose push or pull, and ALSO make off-site read-only backups of the backup server every once in a while.