Being robbed sucks but when it comes to digital possessions there's no reason it needs to suck this much.
> I didn’t really trust file encryption because I thought I might lose files because of it and therefore I never enabled Mac OSX’s built-in FileVault hard drive encryption. I should have though. It’d save me from worrying about who’s going through all my files now.
This is a no brainer. I have yet to notice any real performance hit for enabling full disk encryption. Just enable it, make sure to have a long/strong password, and make sure your computer actually locks when you close the lid.
You should never be worried about losing files on a single computer. If they're important then they should be backed up to multiple computers/drives/services. If you're worried about accidentally wiping your laptop when you setup FDE then just make a backup before hand.
> My backup drive was literally NEXT to my MacBook. By sheer luck, I had just backed up my internal drive the day before and they didn’t take it.
Offsite backups are a must. It can be your own "offsite" (ie. a server at friends/parents/office) but it needs to be somewhere other than the primary site.
> I didn’t have a cloud backup because I don’t trust a third party with my data.
There's nothing wrong with not trusting third parties but that's exactly what encryption is for. Encrypt your data locally and then you can store it remotely without worrying about it being accessible to a third party. DIY scripting with GPG/S3 works well for a lot of situations. Or you can just use Tarsnap[1].
Honestly it makes a lot of sense to do the same with USB drives as well. My Linux machine is my primary computer (OS X laptop when roaming...) so the majority of my backup USB drive usage is done there. I have them setup with LUKS/dm-crypt[2] for full disk encryption. It's really easy to setup, plug-n-play on modern systems, and it almost falls into the "no reason not too" category. I just wish OS X supported it too.
> This is a no brainer. I have yet to notice any real performance hit for enabling full disk encryption. Just enable it, make sure to have a long/strong password, and make sure your computer actually locks when you close the lid.
I have confirmed, using dtrace, that OS X uses Intel's AES-NI instructions to accelerate encrypted disks. I found no performance decrease for batch file copies. I did not test small files nor seeking. I should run more benchmarks now that I have an SSD. Perhaps the CPU is now the bottleneck.
Depending on your threat model, they don't even have to be outside the house. If petty burglary is what you are defending against, a disk in a quiet corner of your basement is probably plenty.
I bring up threat models a lot, because I'm still fascinated with the model of data security as an adversarial relationship in which you can characterize your enemy, and thus qualify "good enough".
> Depending on your threat model, they don't even have to be outside the house. If petty burglary is what you are defending against, a disk in a quiet corner of your basement is probably plenty.
Being outside of the house protects it equally well against fires/floods/earthquakes/pets too. Protection against burglary is an added bonus.
Oh yes, being somewhere other than your house has very clear upsides, but an appropriate location is not always forthcoming. For example, I would consider it pretty poor form to plug in a personal networked backup box at my desk at work. That kind of move can also pose a risk to my sustained employment!
> Oh yes, being somewhere other than your house has very clear upsides, but an appropriate location is not always forthcoming.
It's not too hard to find one. Unless you're completely anti-social you probably have at least one tech-savvy friend that can understand the need for this kind of setup. Even better if you have more than one friend (hopefully not too be an "if") then you can have a "round robin" approach with a group of friends. An open source (so the crypto can actually be vetted) version of BTSync[1] would be great for this.
> For example, I would consider it pretty poor form to plug in a personal networked backup box at my desk at work. That kind of move can also pose a risk to my sustained employment!
Haha. Yes plugging in random networked boxes at the office might arouse some (just!) concern. When I wrote that piece I was thinking specifically of my company as I'm the boss :D
> An open source (so the crypto can actually be vetted) version of BTSync[1] would be great for this.
I'm most of the way through the non-Bitcoin / "Disk Space Marketplace" portion of a project that would work really well for this[1].
While the premise is that you would be able to rent disk space from anyone who wanted to provide it (using Bitcoin/Stripe/PayPal/Whatever), that part is going to be decoupled from the actual encrypt + distribute portion which could be pretty easily used by a group of friends to have reciprocal backups of important data.
I'm still a couple weekends away from it being usable though.
Git-annex does encrypt if you set the other site(s) as a special remote - a good way to use it with less technical friends is to get a Windows rsync server (there are some with simple GUIs for start/stop) and set that machine as an encrypted rsync remote.
Although I don't do it as regularly as I should, one compromise is to periodically backup to a USB drive and stick it in a drawer in your office. If you remember to update every few months or so, you may lose some recent things if you lose everything that you backup realtime but that's a big difference from losing everything.
I do use offsite backup in addition to regular local backups. I genuinely wonder how this will play out as video and image stuff to backup grows. At the least I'm thinking I probably need to do a better job of figuring out how to separate the important stuff from all the intermediate, rejected, etc. files.
My sense of pity really was cut short by not encrypting things. Regardless of the mention/data that disk encryption is a minor hit, reality is, for most it would be a non issue...our day to day computing issues aren't going to stress Filevault. Just turn it on...that or keep sensitive stuff in an encrypted disk image.
There is a lot in this story that sucks but a lot that is "should have known better" as well.
Cyphertite[1] works very will for encrypted backups.
It splits your data in chunks, encrypts them on the fly while sending them to the cloud. It doesn't use much space, apart from a little metadata, and you don't have to worry about the NSA, as the encryption keys are only on your local machine.
Safety deposit box at a bank, trusted non-local family member's house, and trusted international (preferably different continent) friend's house should be enough for most cases.
A good way to keep your files secure without using encryption is running anything else than OSX or Windows, too. I have had two laptops stolen, from my home - once entering by the (closed) door, once by a (closed) window. With them being under FreeBSD and Arch Linux, I'm quite confident that my data stayed safe (I ihad scans of about all my papers in there). It's kind of security through obscurity, but I think it works pretty well, any disk that's not FAT32, NTFS or HFS+ formatted is quite secure against theft.
Regarding backups, my laptops usually rsync their /home every day to my remote server (and most data on them is in git repositories anyway).
Then perhaps back up the <10 Gb of stuff that would really screw you up if you lose it. For example, I keep all my bank account info, passwords, personal documents on an encrypted hardrive and I further encrypt the files. I keep this off site at a friends house which I can SSH into and transfer what ever I need.
Two 4TB Ext USB3 HD's and a Safety Deposit box at your Bank.
Cheap, more or less convenient (get four drives and rotate your backup drives), and secure.
Easier yet if you can pair the amount of crucial stuff to under 4TB, then it's just one drive that you can rotate monthly (weekly?).
WTF 8TB? Are you a movie editor or something? Anyway, I'm sure you don't change 8TB of data regularly. Back up the 7,9TB which is stale on a physical media you store at your parents', then set up online sync for anything new you produce or change.
How little "offsite" can one get away with? Could you put a waterproof (flooding), fireproof, buried (tornadoes) safe with a NAS (SSDs for earthquake protection?) in the barn in your yard? It would be easy to run Ethernet to that and have fully synced backups without ISP/cloud service charges.
What natural disasters/events will take out both your home and the hardened safe in your barn?
One problem with "fireproof" is that a safe that will protect paper records against combustion (by shielding them from the most intense heat and preventing oxygen from entering) will almost certainly get hot enough to melt plastics and render magnetic storage damaged if not unreadable.
One of the characteristics of fireproof safes is also their ability to withstand a multi-story drop. The reason being that when the floor burns out from under it, that's what happens. This still doesn't do much to ensure data records are retained.
So long as it's a barn in the yard, reasonably directional WiFi might well suffice.
As for what natural disasters could take out your house and your barn: if you live in wildfire country, that's a distinct possible risk. As a random Google Image search example:
Not always. Fireproof safes are rated for paper, tape or drives, as well as a time limit. A safe rated for drives will guaranteed a maximum of 55 degrees (C) inside it for the rated time, enough for drives to survive without problem when powered down.
Fair enough. Much of my experience is pretty dated, to the beginning of the time that data storage was a major concern (and much of the data of the time would do just fine in a paper-rated safe).
You do raise the point that fire ratings are for specific time limits: X minutes at Y temperature.
Another key point (my long-ago sources informed me) is that one of the most important things to do after the fire is to NOT OPEN THE SAFE (this applied to paper storage, inquire with your vendor / manufacturer for data).
The same properties which make a safe proof against fire damage mean that it retains heat once applied to it for a considerable period. Apparently it's not uncommon for people to employ a fireproof safe, secure their papers and documents within it, have the safe and documents survive the fire ... and then spontaneously combust when fresh oxygen is introduced on opening to the still-blazing-hot interior.
The issue there isn't that something unlikely will happen physically, such as an EMP, the issue is that a virus could take out it out at the same time as it hits your main machine, thanks to that ethernet cable.
> I didn’t really trust file encryption because I thought I might lose files because of it and therefore I never enabled Mac OSX’s built-in FileVault hard drive encryption. I should have though. It’d save me from worrying about who’s going through all my files now.
This is a no brainer. I have yet to notice any real performance hit for enabling full disk encryption. Just enable it, make sure to have a long/strong password, and make sure your computer actually locks when you close the lid.
You should never be worried about losing files on a single computer. If they're important then they should be backed up to multiple computers/drives/services. If you're worried about accidentally wiping your laptop when you setup FDE then just make a backup before hand.
> My backup drive was literally NEXT to my MacBook. By sheer luck, I had just backed up my internal drive the day before and they didn’t take it.
Offsite backups are a must. It can be your own "offsite" (ie. a server at friends/parents/office) but it needs to be somewhere other than the primary site.
> I didn’t have a cloud backup because I don’t trust a third party with my data.
There's nothing wrong with not trusting third parties but that's exactly what encryption is for. Encrypt your data locally and then you can store it remotely without worrying about it being accessible to a third party. DIY scripting with GPG/S3 works well for a lot of situations. Or you can just use Tarsnap[1].
Honestly it makes a lot of sense to do the same with USB drives as well. My Linux machine is my primary computer (OS X laptop when roaming...) so the majority of my backup USB drive usage is done there. I have them setup with LUKS/dm-crypt[2] for full disk encryption. It's really easy to setup, plug-n-play on modern systems, and it almost falls into the "no reason not too" category. I just wish OS X supported it too.
[1]: http://www.tarsnap.com/
[2]: http://en.wikipedia.org/wiki/Linux_Unified_Key_Setup