Showing posts with label support. Show all posts
Showing posts with label support. Show all posts

Friday, January 20, 2017

Disaster Recovery (Updated)

It had so much potential


Updated 12th March 2016. Newly added notes at the end of the post.

Back in 2014 I needed to choose a robust backup / DR solution that would help me prevent loss-of-hair & brown trouser moments - e.g. ransomware or user stupidity (my own mostly). All sorted and was fortunate enough to choose one that still covers my needs.

However since then I flirted with a couple of alternatives and ended up settling on a selection of cloudy storage options.

For the personal stuff I tend to use the big names (Google, Microsoft & Apple) which are linked into device accounts. These are really low-risk, low-value data items which business adversaries or other intruding agents [hackers] would find worthless.

However there's a lot of information which is business-focused - or that which is protected under one of my businesses ICO Data Controller registrations - which need more attention.

The reason I'm writing about it now is because since evaluating options I've moved away from Windows, so the requirements are now vastly different. So because I'm primarily focused on multi-platform solutions a lot of the offerings get defenestrated immediately.

Over the last few months I've been prodding and cajoling Tresorit to fix problems with their Linux client and have now officially given up. No responses from their support desk about quite critical issues in some time. One of the issues is that - whilst I had Visual Studio Code running, and doing some project work on a Python module - Tresorit started to sync one of the tresors which houses project work.

I watched in horror as the file list started reducing in number in VSC - it was like an unstoppable terror of code deletion. Anyone who's just discovered that code they've spent days or weeks applying themselves to is lost forever will know that feeling.

At first I hadn't made the connection between Tresorit and the file emigration but then I did a sudo find / -name <scriptname> only to see it right there. In a .tresorit/Trash/.. folder!!

Nope.

Not having that. Recovered all files - and a bunch of others I hadn't spotted were missing yet. Immediately closed Tresorit and fired up my previous DR solution. It took all night to get everything back up to sync and this morning to verify everything before ditching Tresorit completely.

Crisis averted. Still no response from Tresorit despite what now appears increasingly arrogant claims vs. it's competitors in the market. The Linux client came out of beta mid-2016 so should have been rigorously tested.

It's a real shame and I'm extremely disappointed - I really like that they have 2FA across a choice of mechanisms, and claim zero-knowledge across the entire platform (including via the web client - although this is unconfirmed). I'm not concerned with state actors as I've done nothing wrong but I need something that keeps competitors or their agents out - Tresorits Swiss & EU base fits this ideology too. I like the tresor mechanism of sharing and I'm now trying to frig something similar with my DR solution.

Perhaps their Windows and Mac clients are far better at this than their Linux offering so it might be unfair to tarnish their entire platform, but the lack of support (and wasted subscription fees) eroded my trust and after all, what is DR without faith?

Updates

I noticed that Tresorit tweeted a marketing message about feature enhancement, which - to me at least - seemed to confirm that they were essentially ignoring my bug notifications and support requests. I replied to the tweet and the account owner asked me for some details via DM.

After hearing nothing for a few weeks I prompted the Tresorit Twitter account again - this time they promised a response from their support & dev team. Five months to get a response from vendor on a critical issue (and only after complaining on social media).

The explanation given via email was more unsettling than the problem itself - they could not replicate the issue and that some fixes applied since November 2016 'may' have resolved some of the problems. What I take from that is that although none of the fixes were specifically aimed at resolving the problems I reported, they want me to see if they fix it.

In the same email the support member tried to tell me that I must have deleted the files from the tresor on a different machine, which triggered the removal on the machine in question. The problem with that is that I hadn't deleted any of the files on any other machine. The files in question were / are live code files related to an anti-spam module & reporting system I've been designing and writing - there's no way I would delete these files - I've put so much effort in. The other files I found after checking other tresors for mysteriously deleted files were legal documents I would never delete under any circumstances. I rechecked the other machine and I hadn't deleted either set of files there.

Tresorit's support suggested I check the logs - which I did - to see if any files were listed as deleted by user(s). They weren't. Essentially it was just the DR system wrongly flagging files as deleted and that removes all confidence I had using the platform in the first place.

I've since replicated what I liked about the tresor repository system within Spideroak One.

Overall, it's vindication that I made the right decision in abandoning Tresorit altogether, although I'm still wondering what was deleted that I haven't noticed yet.

Tuesday, October 18, 2016

Running VMWare Player on an Ubuntu 16 SP4


I had some minor headaches trying to get a decent hypervisor working on Linux desktop, and figured out a more manageable approach whilst retaining secure boot & UEFI.

One of the initial challenges is actually getting to the download for the VMW Player - rather than the full (paid for) Workstation etc. but can be found here at the time of writing. VMWare seem to have made it far simpler to access than when I first dug it out. NB this is only for non-commercial use, otherwise you'll need the paid-for Pro version.

Had to use Chromium as FF didn't want to play with vmware.com
Of concern for me was the lack of checksum or PGP verification for the download, something VMWare need to work on. The other major annoyance is that every time the kernel is updated this process needs to be repeated.

High-Level Views

The reason you may need to do this is that you've tried to use VMWare Player / Worktation but the networking does not work. After digging into your logs you'll see that the drivers couldn't be loaded at boot time.

Unlike VirtualBox et al VMWare seems a lot more stable on my SP4 i7 16GB, and can run multiple VMs without the need to have their UI windows open. It also seems to handle host-guest device management (e.g. USB) far better.

Personally, I was tired of VB being flakey and am used to VMware and Hyper-V.

Step-by-Step

  1. Download the VMWare bundle from the link listed above
  2. Apply executable permissions via sudo chmod ug+x <vmw.bundle> 
  3. Run the .bundle (it's just a shell script) via sudo ./<vmw.bundle
  4. Once the installer has completed you may need a reboot - if you do you'll see systemd errors relating to failed service starts for the vmware.service due to the unsigned network drivers vmmon / vmnet 
  5. You'll need to run the kernel module updater - either via GUI or via sudo vmware-modconfig --console --install-all - this ensures that the modules VMWare needs to operate it's core networking capability are available
GUI version of the installer is invoked if you try and run the player at this point
This step should produce a script output ending something like this:
Starting VMware services:
   Virtual machine monitor                                            failed
   Virtual machine communication interface                             done
   VM communication interface socket family                            done
   Blocking file system                                                done
   Virtual ethernet                                                   failed
   VMware Authentication Daemon                                        done
Unable to start services
 


Checking the status of system services should show vmware loaded but unable to run.
This indicates that everything is ready for signing now the modules are ready. After step #5 download or clone a copy of this signer script and follow the instructions. You will be asked to create a password during generation, which is then requested during MOK install after you reboot.

Expanding on That

The last item on that list is a bit abrupt but there's a couple of things you must do. Firstly you need to adapt the certificate definition to your own needs.

Change the subject of each of the certificates from "/C=CountyCode/ST=OfficeState/L=OfficeCity/O=Dept/CN=local.yourdomain.ext" on line 9 as appropriate to your specific needs. Ensure that these details are not accessible by anyone other than yourself.

Two certificates are generated - one for each driver. You can simplify to one certificate if you prefer.


Problems


  1. Errors during step 5 could mean issues with VMware version and the Linux version. I upgraded to Ubuntu 16.10 which upgraded the kernel. To solve issues in error messages with the VMW kernel module updater download the latest version of the VMware player
  2. I found that a reboot was needed between dist-upgrade of Ubuntu and VMware re-sign, otherwise something would get itself tied up in knots and have no effect on the player.

Sunday, October 16, 2016

Old News

I noticed a few news articles recently that bemused me....relating to the addition of updates to v4.8 of the Linux kernel to support touch screen on Surface Pro 3.

This is strange to me because when I dual-booted my SP3 a couple of years ago with Ubuntu 15, touch screen worked out-of-the-box. Unity and Gnome UIs don't really deal with touch-screen input very well (but Linux doesn't really have the designers that Microsoft or Apple do), but it's not too bad. The SP 3 pen right-click isn't recognised at all so you'll need a mouse anyway. I included a photo of this in operation from a much earlier blog post.

Ubuntu 15, using the SP3 pen as a mouse
 However touch-screen input doesn't work at all with the SP4 - Running Ubuntu 16.04 and Gnome - no direct touch or pen input is detected. I can't find a touch-screen device registered by the OS either so am guessing this is the lack of drivers / support from Intel for the Iris 540 and touch-screen itself.

When I get some time later this month I'll look at the Intel Linux driver programme and the latest kernel to see if there's progress.

Thursday, January 01, 2015

MSXML 3 Control Panel Killer


I've got a few posts in the pipeline at the moment thanks to the generous time I've had on hols, but one thing caught my attention whilst fixing a problem on a Windows 8.1 Enterprise desktop.

I use Secunia to help keep an eye on installed software - it can be difficult to keep track of all the software installed sometimes, and this solution seems to cover various types of installer (including EXE's copied into a folder, without any associated registry settings).

So after running it and getting caught up on some minor version changes it also pointed out that there was a deprecated version of MSXML v4 deployed and after some laborious - but necessary - ownership and permission changes in SysWOW64 / System32 directories, I'd removed the MSXML v4 libraries. Of course that's never enough - Also noticed MSXML v3 so did a bit of digging into the upgrade path to version 6 (most of which dated back to 2007). No indication of warning signs.

So some more ownership & permission changes followed by some deletes. All fine.

Some time later.... I had cause to make a networking change and tried to open the Network and Sharing Center... hmmm. Nothing happens.

I try a few other control panel items and get a mix of results but most of the really important control panel pages aren't working. Some just aren't responding, others open the dialog but have particular tabs throwing exceptions about panel pages.

So aided by a bit of digging around I find the reference to the system file checker (sfc) - Always have a look at the command before you run it (rather than just doing what a web page tells you to...ironic considering this is a blog post). I hadn't connected the dots between MSXML and the problems at this stage so was curious about the log file sfc /scannow would generate.

000007c6 [SR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\WINDOWS\System32"\[l:22{11}]"msxml3r.dll" from store
000007c7 [SR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\WINDOWS\System32"\[l:20{10}]"msxml3.dll" from store
000007c8 [SR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\WINDOWS\SysWOW64"\[l:22{11}]"msxml3r.dll" from store
000007c9 [SR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\WINDOWS\SysWOW64"\[l:20{10}]"msxml3.dll" from store


There it was - literally as simple as that. Of course now everything was working as expected I did what I should have done first and read up on the MS Xml Parser roadmap.

Moral of the story...If it ain't broke, don't fix it. (especially if you have a cold and know you're not operating at 100%)

I'll post less dumb things as soon as I've got Kali set up on my new Pi B+. 

Friday, October 24, 2014

Firewalls, IDS and sticky tape


More Surface Pro blogging....

I had some issues with some of the Windows 8 apps that rely on Xbox Live sign in - Most seemed to take ages to sign in and others refused to sign in at all (SmartGlass in Windows 8!!!). I'd been poking around BitDefender and just couldn't deep enough into the configuration so removed it and went back to ESET.

After fiddling around trying to resolve SmartGlass sign in error 0x3ec with no success, I made some changes to get everything else working...SmartGlass now shows error 0x3ea and I've stopped wasting any more time on it.

[Please note - SSL scanning in original post, but see update comment at end of post]
Long story short - I often enforce an SSL scan (just because a service uses secured transport doesn't mean someone's cocked up something within the delivery), and this was basically what was causing the issue. After adding some certificates as trusted or excluded the whole sign process was fine.

Excluded certificates: login.live.com, storage.live.com
Trusted certificates: none (other than what you already have)

Not happy that some certificates have to be excluded from SSL scanning but a leap of faith needed to get features operational. Don't forget to disable all obsolete versions of SSL (TLS 1.x > only!) if the option exists in your security system.

In addition to that firewall rules need to be added for outbound traffic.

Application: {windows}\system32\WWaHost.exe
Application: {windows}\SysWow64\WWaHost.exe
Protocols: TCP
Ports: HTTP, HTTPS (ports 80 and 443 by default)
Direction: Outbound

The net result is that I have Windows 8 applications working and still isolated by the OS, IDS and SPI features working. There was an issue with a previous version where if your Xbox was wired to the network and you were using wireless for your SmartGlass device the two could not communicate - They needed to be on the same wireless network. I can understand why that might have been done but it renders the features pointless for me (it just doesn't fit the topology we need here at home).

As I've invested too much time already in SmartGlass I just uninstalled and moved on, but the rest of Xbox One, 360, SP3, Windows and WP are operational again.

Update 25-07-2015

I've now disabled SSL scanning in a few security suites due to concerns about privacy and chain management. A number of well thought of systems will not work with SSL scanning enabled (due to the way in which many security suites insert themselves into the chain). The firewall rules mentioned here could still help you but I no longer recommend SSL scanning
As part of my study for things like CEH I'm building a home IDS separate from these software components - these suites are fairly good for most people but anyone who does a lot on their home networks should consider defence-in-depth these days.

Saturday, October 18, 2014

5 Ghz Wifi & Surface Pro 3

I've noticed a trend with SP3 users over the course of its life so far, and there's been a few issues initially relating to overheating, pens, over-eager power saving and wireless networking.

Whilst I feel fortunate to have missed out on these problems in only buying after the first big batch of firmware and software updates I've still been struggling with the 5Ghz band Wifi issues; that is, until now.

Basically I've had WiFi problems with Windows Phone 8.1 and Surface Pro 3; although not Surface Pro 1 funnily enough. A registry hack enabled visibility of 5Ghz networks on the SP1 but after recent WP8 updates I've not been able to acquire those networks any more. 2.4 Ghz is fine, and if separated from the router by more than one or two solid walls (esp. re-enforced concrete) 5 Ghz is next to useless anyway. I'm not going into details here but you can read about it on StackOverflow if you're interested.

However 5 Ghz is great for the same vicinity plus network storage / high data transfer, which is why I'm interested in getting it working over our home network. After two weeks of frustrated router settings experiments I found the solution whilst browsing with my Saturday morning cup of coffee.

The answer lies here on the Windows 8.1 Forums over at Microsoft. Now whomever UKNOWJP is, they deserve a medal - it only solves the problem on networks where you have privilege to change the router & AP settings but on your own network it's a winner.

There's all sorts of answers on the web about deleting drivers, updating router firmware, messing around with recovery partition driver versions....all valid solutions to other specific problems. However across all the different devices and patch versions I found across the forums this one was unique in that it solved the initial problem.

Just change all 5 Ghz networks channel numbers to below 100 - channel 36 is suggested in this post (you still need to use different channel numbers for different networks on the same frequency).

Don't forget: Reboot the router after you've logged in to the admin area and changed your settings; this prevents any possibility of latent session capture by unwelcome guests.

Now Windows Phone 8.1, Windows 8.1 (SP3 and SP1) all see every single WiFi network our routers provide...but it's not a silver bullet.

Prior to this I hadn't altered the channel number on the 5 Ghz networks so above channel 100 was the default setting. If that's the case we cannot guarantee that all networks of this frequency will enable contemporary Windows devices to connect - this only appears to be a problem with AP's running the 802.11ac protocol afaik.

Overall I think Microsoft need to work on some updates which don't have this channel number requirement - and disclose why this problem exists.

Addendum: I haven't checked this with iPhone yet, my better half has a 4S - that and iPhone 5 weren't 802.11ac capable...Will update when she gets her iPhone 6 to see if these settings are compatible.

VMWare Player Memory Issues


I had a *facepalm* moment with VMWare Player yesterday and solved it today so thought I'd share it - Either that helps someone out or makes someone laugh at my stupidity (either way it's a positive post).

I've recently been getting things deployed to my brand new Surface Pro 3 and by and large it's been painless - almost everything Windows 8'y was done instantly because of the settings sync between my Surface Pro 1 and my various desktop and R&D VMs using the same Microsoft Live ID. It's optional of course but I found that it makes a positive difference1.

The only installs I've had to do are the standard laptop / desktop installs, e.g. Visual Studio, Achimate, EA, Office, etc... And VMWare Player2.

None of these were an issue but when trying to spin up a VM I kept getting an error message telling me that there wasn't sufficient memory for the VM guest. I'd already moved VMX across from old Surface or installed new VM's from scratch so it wasn't happening all the time.

I thought that was a bit strange as my Linux guests tend to have 512Mb RAM for sandboxes and up to around 2Gb for intensive operators (such as some research tools on Kali). With 8Gb of RAM on SP3 and a few days researching memory cache in Win8.1 I was pretty confident that this wasn't the real issue.

Which of course it wasn't. Finally found this conversation chain on the VMWare forums.
Well that made a lot of sense. Should have checked UAC issues out first. I changed the application start-up options via context menu properties on %installPahth%\vmplayer.exe to run as administrator ... restart machine and - lo and behold - it seems to kick it into touch.
Hope that saves someone else the time spent on the problem :)

Wednesday, September 24, 2014

Council Tax: The Saga Continues

So despite being promised a response with 15 working days by Lisa Atkins ... I've received nothing. Perhaps they want to sweep the whole affair under the carpet? No-one likes seeing their ineptitude blogged about.

I may prod them next week after I've finished laughing about the "new" iPhone.

Saturday, August 23, 2014

Auto-Archiving IMAP in Outlook

It seems like I'm not alone in initially being surprised that IMAP accounts cannot be archived in Outlook.

After spending some time poking around forums, Q&A sites and product support pages it's as simple as IMAP and archiving are mutually exclusive. I thought I'd put a concept forward for anyone out there who needs both the convenience of externally hosted IMAP functionality as well as the maildrop & delivery capability provided by the POP3 system.

A typical example here for me is wanting to access the same email account across multiple devices, get alerts on incoming messages on those devices, and be able to reply should I need to.

I also want to be able to take an archive of older emails (receipts, legal conversations, audit items, records of business and conversations, etc) and store separately for a given period too.

So in order to get around this I use IMAP almost everywhere but then on one (perhaps two locations) I'll connect via POP3 over Outlook - use whatever email client you wish - and use the auto-archive facilities to create email archive files.
Application and Service Relationship

These files (PST) can then be added to an offsite backup. An IMAP account in Outlook will use an OST file to cache mail items and headers but if its deleted or lost your IMAP account is unaffected.
Archive and Artefact Relationships
 

Tuesday, August 19, 2014

Council Tax

How I'd imagined Birmingham Council Tax team to appear on Monday mornings
Have you ever had a situation where your council have incorrectly billed you and take an enormous amount of time to get back to  you - never mind resolve the situation?

Have you ever become frustrated with local government civil service ineptitude, broken record response, their lack of productivity and their incredible inefficiency?

Have you ever received threatening letters from the council, perhaps attempting to coerce you into overpaying something with the threat of a court appearance?

Well, I may have a couple of pointers to help you out.

In the first instance, obviously try and get the other party to engage in the issue and make reasonable attempt to move the situation along. For example, I tried phoning the council and was told I couldn't close the account and get a final bill until I provided the next tenants details. As I no way of knowing this and they wouldn't take the management agents details, I was told there was "nothing we can do" by the person on the other end of the phone.

Even though I told him that it simply wasn't my problem and followed it up in an email to confirm, they still tried bill me after I had vacated the property. I even explained that no other city I've lived in has ever tried such a ridiculous trick to save themselves investigating the deeds.

So ... what next?

Firstly, take the name at the bottom of the automated council tax letter you've just been unnecessarily sent - Usually its from someone nominally senior to make the letter more official, threatening court action if you don't comply. In my example it was stamped from Chris Gibbs, the Assistance Director of Revenues and Benefits.

You'll need the domain name they use as well - Do a web search for "[insert city name in here] council tax" and it should be amongst the top results - it'll usually be the same as the council tax website where you live. In my example its "birmingham.gov.uk".

Put that aside and try the usual routes of approach - I tend to avoid spending my own money on hold over the phone with various departments, who only tell me to fill out a form; and email directly. Don't expect rapid responses but it means you're getting everything in writing.

In this case it took a fortnight just to reply to an email.

Now when this inevitably fails - After hearing every excuse under the sun no to add single person occupancy discount, or close the account due to you moving out, etc, start forwarding snarky emails to the semi-important nominee you found on your letter.

Try the following:
  • firstname.surname@domain name
  • [letter of firstname].surname@domain name
  • [letter of firstname]surname@domain name
  • firstname_surname@domain name
  • ...and so on.
You'll end up with an email with a lot of recipients perhaps - try about five at a time. When one of the addresses does not return a failed recipient error email from the council email server you'll have found the right email address.

In my example it was as simple as chris.gibbs@birmingham.gov.uk - as you can see from the email I eventually got from his PA.

Now and then you may get the occasional attempt at derailment, or just plain mishaps with technology...such as your email vanishing in a puff of smoke. Example here. Apparently between replying to my email acknowledging receipt and then actually getting around to looking at it / forwarding it, the content had vanished. Electronic trickery. Clearly sorcery at work.

Finally, after five months end-to-end, malcontent with the situation and happy to demonstrate the level of ineffectualness to the courts; the council emailed me back. Very forthright and here it is.

I've waited a while to respond and ensured more people had access to the email address - Maybe it might help the council deal with queries faster - It certainly got past the evasive and disinclined lower ranks of the city council for me.

So all it took to add single person occupancy discount to the council tax bill and close the account in order to send me a final bill was my prompting, cajoling, returning legal threats in kind, involving the department deputy head for five months.

It took six minutes to pay in full electronically from my tablet.

Even now Chris' department are attempting to coerce me into paying council tax for a period after I moved out. Guess its time for another email...

Update 2015

After a few months of hearing nothing I got a bit suspicious - I'd created enough attention now that the issue would surely be resolved (only took a year). Unfortunately it had: The council had ignored my proof and raised a claim in the courts without notifying me. By the time I found out about it a collections agency contacted me. I'm not sure how legal that was because I would have been extremely happy to represent myself in the courts - after all, plenty of public evidence.

My advice here would be to email and call every week for an update to check that your council weren't trying to pull a fast one, I didn't and got caught out procedurally.

The net result was that I had to pay for the con-job letting agents portion of the bill as well as my own. I suppose it was more the principal of it than anything else as the money involved was negligible (only around £200) but local government defeated me by knowing how to take advantage of the system in order to absorb their own broken processes.

However, if you fall foul of a similar situation don't forget; don't waste your time with the 9-5 mob at BCC as they'll just have you chasing your own tail. Go straight to Chris Gibbs so you can get a response, and he can be reached at: chris.gibbs@birmingham.gov.uk - best of luck.

Friday, August 15, 2014

Simple Backup Follow up: Part 2

Ok so having sifted through roadmap candidates I was left with Carbonite, SpiderOak and Backblaze.

As I mentioned in the first part of this piece I've got some very specific [picky] drivers and requirements for this solution.

Carbonite seemed pretty good overall but the price is an issue. For £34 a year (or thereabouts depending on the forex rate) you get to backup only one device. Even the next package up at around £60 a year is restricted to one device.

However for that you get unlimited space on your single Windows or Mac machine. It's not bad but I'm aiming for something that isn't as restrictive to cover my secondary drivers and requirements. To do that I'd have to take one of the Pro Plans, which start at £162 per year. That covers an unlimited number of devices but is then restricted to 250Gb.

It's an option but I'm discounting it for now as I'm going for something cheaper - perhaps even considering Carbonite alongside Datto for an enterprise-level candidate. My concern there is for non-US customers as they have stateside support only according to their website.

So down to two, both of whom have trials available.

I started with Backblaze as it seemed to cover all aspects. The review from the original cloud storage reviews list stated that Backblaze doesn't have a single-point encryption key to match some of the other products but I think the vendor has added the feature since that review.

All fine - good price: Either £3 per month for an essentially unlimited storage quantity, or £9 for the year. I actually thought I need look no further - and for most people this will probably do what you need it to do with minimum hassle. It's pretty easy to use ... but the problem is that I couldn't use it the same way I could with Mozy Pro and define specific backup sets of files and folders. I need a selective DR option and this would take too much time to configure.

With Backblaze I found it would back up all drives, but then allow me to isolate exceptions to the rule to exclude from future backups / delta chains.
Inverse selection....Choose everything then remove everything you don't want
 If it wasn't for that small issue I would have signed up there and then. If you don't have such restrictive requirements and are looking for something safe and cheap you may want to take a look at the options this vendor provides.

My last option was actually added after further research whilst trialling Backblaze, and does exactly what it says on the tin (what I'd call "a Ronseal job").

Whilst the free 2Gb, unlimited devices, hive capable, secure and fast capabilities seem great;  A word of caution: The two-factor authentication is limited as this is a US-focused product too - you cannot use the two-factor authentication unless you have a Canadian or US mobile number. I can get around the problem as I have infrastructure and phone numbers in the states but anyone solely based in Europe would need to review and balance capability over protection.

The vendors engaging the wider FOSS community with outer shell tools and libraries from their product. There's a description of the encryption and hashing algorithms implemented within the web-gumpff pages if you want to read it in detail. Its impossible to tell exactly how they're managing the information protection aspect of the implementation from the sales page but use of CFB is interesting. Works for me.

The only problem I have with that will be future release of open-source libraries used by their main products. Open-source is great but without organisation-level QA of each delta there's a risk of insecurity - lets hope that changes with the major corporate push on critical open source projects from earlier this year. We'll see where that goes but for now I'm going to shortlist SpiderOak.

I've read a few reviews that state that the UI isn't as intuitive; or that its quite complicated - I think thats probably relative. Its more complicated that Backblaze, but probably about the same as MozyPro. The UI is consistent on the Debian package as well so I'll give it a thumbs up.

I like that SpiderOak has endpoint installers for my favourite OS across Windows, Debian-based and Android...but no Windows Phone. We'll see how that goes for now as its not a critical requirement. [Update: WP doesn't need it due to the direct integration with OneDrive]

Whilst chipping away at this article I've been running SpiderOak for a day or so on a selected backup set. I had some problems with the SSL scanner within one of my security suites initially, but have since resolved that issue.
The final candidate, operational across numerous devices.
I ran some tests on a couple of other devices and virtual machines. Windows Server 2012 R2, Kali, Windows 7, Debian and a Mac all worked perfectly well. Time will tell but for now that's all boxes checked. I didn't get round to checking how well it works on the Nexus 7 but there's nothing of value on there anyway. We don't have any overpriced paperweights in this house [c.f. iPad].

SipderOak doesn't store plain text backups, encrypts before transfer and encrypts the transport so prevents easy acquisition of my device files and data.

TL;DR

Overall this is the viable candidate for me, and in summary (comparing it against my original key drivers) I can sync and schedule backups separately, or link the events together - with a per-machine sync schedule. There's a zero-visibility policy meaning only I can unlock the secured backup sets. I can have 2Gb storage free forever - Although I've now signed up to the annual 100Gb package for £60. Its more than I was paying for Mozy Pro but I get more for my money, better support availability and unlimited device capability (including mobile and virtual). I can pick and choose where to restore specific files from any device in my list.

All the candidates I looked at were good products but this one suited my needs better than the rest. I'd be really interested to hear other opinions.

Thursday, August 14, 2014

Simple Backup Follow up: Part 1

Having ditched Mozy Pro after trials and tribulations described in an earlier post, I've started looking at alternatives.

I've had no response from MBW or Mozy regarding my password reset or product code requests so couldn't get any further with the uninstall / reinstall process. Needless to say that I haven't got time to spare dealing with the problem, so am looking at other solutions.

Anyone facing a similar choice of offsite backup solutions may find the results useful, but I found this comparison quite a useful starting point. Personally, I'm always a little suspicious of who paid for advertised reviews and which reviews are genuine; so found this list that contained a wide range of solutions.

From my perspective, the term "cloud" is a sales buzzword for architecture that has been in existence for at least a decade. "Cloud", "cloud hybrid", "private cloud" essentially just means "hosted" - With a combination of outsourced hosting or private / internal hosting infrastructure.

Moving past this, the objective of the exercise is to find an offsite / cloud backup solution for personal use - perhaps even a vendor that provides appropriate personal and enterprise-grade solutions. Obviously this is a very specific set of requirements, and yours will be different.

I'm aiming for the following drivers in order:
  1. Ability to synchronise and schedule backups, potentially even machine restores
  2. Price
  3. Security (I'd like a secured backup that only the key-holder can open)
  4. Capacity
Optionally, some secondary drivers would be nice:
  1. Capable of backing up specific folders / files from a number of devices or VM's
  2. Capable of restoring specific files to a device of my choosing
So where to start? Well Mozy Pro is discounted immediately. Whilst it seems to cover the main drivers it seems to miss out on the secondary drivers. Also my own experience has been tainted by the difficulty in solving a problem originally reported in 2010. If I had problems with Windows 8.1 Enterprise I'm not prepared to wait it out or see what happens with Windows 9 upgrades.

After doing some research I'm going to cut the list down to 2 candidates, although I focused on the following roadmap candidates to begin with:
  • Carbonite
  • Backblaze
  • Datto
  • OneDrive (Sky Drive)
  • SpiderOak
For me, the whole OneDrive / Google Drive / Dropbox mechanism is great for a specific purpose - storing a bunch of files and folders online (or "in the cloud" if you must), and sharing across devices. We have a large proportion of Microsoft devices in our household, along with an iPhone, a few Linux boxes and some other kit I use in my sandbox.

OneDrive is great for allowing the share of files I've acquired on a PC to a sandbox machine on a different VLAN. Its also perfect for being able to capture, modify sales documents written in MS office on Surface Pro, desktops and Windows Phones.

However I've discounted this type of technology almost straight away because I'm looking for a dedicated backup & disaster recovery option for some very specific file sets. Windows 8/8.1 already takes care of things like apps and settings. I've also discounted them because it would be conceivable that MicroGooHoopleTM could allow access (by subpoena, for example) to those backups - don't forget that everything is based in the US your data is liable to US law.

Obviously that last statement is really within tin-foil hat territory :)

I'm also eliminating Datto as it's clearly an enterprise-grade solution (and has no prices on the website!). EtE encryption, Atom 2.4 Ghz 8 core processors on the backup servers, backup chain recovery, bare metal restores, etc.

In part 2 of this post I'll look at the remaining roadmap candidates:
  • Carbonite
  • Backblaze
  • SpiderOak
 So far I'm also seeing encouraging alternatives for all the MBW features I use and will speak to one of the vendors to take the services outside of the MBW package. Great when its all working but appalling when you need assistance.

Tuesday, August 12, 2014

Simple Backup

I've just returned from a family holiday in Italy to find that my offsite backup for non-essential files still isn't working. I thought I'd leave it after making some system changes and seeing if it resolved itself.

It's pretty simple - All it needs to do is take deltas of selected folders and ensure the latest changes are kept securely offsite. If a PC goes up in flames then I can just restore the important photo albums, etc without much hassle. For more important or critical backups I use other corporate solutions but for the low sensitivity stuff I use MozyPro.

So ever since I restocked a PC with a new SSD and rebuilt with Windows 8 Enterprise I've been having issues - not with the hardware or operating system - but with the backup software. It's not so much that the software is a problem but the support and offered solutions that I have a problem with (or perhaps more that people are being given such terrible advice).

So it started with an innocuous error message "FilesystemError4".... Nicely labelled but with no real indication of what it means in any of the application event items. It does, however, link through to the equally useless expansion of the error category:

So I had a look around, ran some check disks, used SanDisks own disk evaluation tools for the Extreme Pro....no hardware issues at all.

As there was little or no explanation from the application I tried a few searches and quickly discovered this was a reported issue back in 2010 - apparently with no resolution. People were being told to get a replacement hard drive from original vendors, run check disks, restart computers....For some it appears that netsh worked - Mozy actually suggested that people use the legacy version of their software to resolve the issue instead of attempting to diagnose the faults.

So I clicked the Support link on the application settings page and was taken straight to the MyBusinessWorks page....with no hint of a support link. I tried the chat window only to be told by "James" that I had to contact MBW directly by phone on an expensive non-geographic number.....Not impressed at all. I even asked him for a geographic number to use instead but - either through ignorance or belligerence - he told me that there wasn't an alternative and that I could ask a support representative to call me back once I got through to the support desk.

Absolutely unacceptable!!! Say No To 0870 to the rescue - helped me translate 0845 608 0280 into 020 7253 1649: If anyone needs it, this gets you through to the parent company automated switchboard; select option 2 for MBW support. Good thing I'd not called the 0845 number as I hung up after being sat on hold for over ten minutes.

The fact I'm paying for this service makes me so much happier. Its good to see such bright and enthusiastic direct routes to problem resolution.

Bear in mind I've already bought the service (MBW) and the system (MozyPro) but am unable to raise a support ticket with Mozy, EMC or Decho because I have an indirect license. Awesome.

I'm now working my way through error log messages from the text log of the application. So far I've needed to do the following:

  1. Create a new user with specific permissions on the PC
  2. Assign the new user rights to log on as a service on the PC
  3. Assign this new user logon to the Mozy service
  4. Enable read value / set value permissions to the HKEY_LOCAL_MACHINE\SOFTWARE\MyBusinessWorks\Online Data Backup\scheduling key


Its now getting further that the initial failure on backup start but it shows how inappropriate the error message is - a registry key read permission error designates a FilesystemError4. It looks like another failure during the actual backup relating to HTTPS chunked stream reads is failing, but then its reverting to the registry permission error. Will update the post when I have more but I think I'll be replacing Mozy Pro with a competitor very soon.

Update (12th August)

I'm going to give Mozy / Decho a 24 window to send the password reset request I made earlier, if that isn't sorted I'll wash my hands of it and go elsewhere. My only questions is why is something so simple so painful?

Final Update (14th August)

Still no word from the vendor. I'll post my reviews of alternatives in a later post this evening.