View Single Post
  #28 (permalink)  
Old 03-31-2008, 01:59 PM
heinzg heinzg is offline
Loyal Member
 
Posts: 83
Exclamation

Hi again!

JUST A WORD OF CAUTION to those who will run this script with encryption ON

The key file (script default /etc/zmbac/noread) BACK IT UP & KEEP IT SAFE without it your archives are no more than wasted space on the disk and/or tape!!.

The key generated by the script installer is a 48*8=348bit random passphrase, so unless you have a friend at the CIA and lots of time to recover the data, your archive will be lost.

OH one more thing the passphrase should only be known by "the need to know". Your secrets are only as safe as your passphrase is public!

There is also a small flaw in my scripts security you should know about. When "dar" is creating the archive (takes a while) you can SEE THE PASSPHRASE with "top -c" or with "ps -ef" so be sure to have no interactive shell users on the system at the time of backup.

Now I can sleep better tonight having that of my chest
Reply With Quote