this post was submitted on 19 Jun 2026
34 points (94.7% liked)

Selfhosted

59999 readers
456 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam.

  3. Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.

  4. Don't duplicate the full text of your blog or git here. Just post the link for folks to click.

  5. Submission headline should match the article title.

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Let's say you have access to a remote machine and use it to copy backups occasionally, eg with rsync. Your local machine has credentials stored that allow write access on the remote machine, however if the local account was compromised that could also allow access to the remote machine and the data stored there.

How can you grant access to an account to write remotely, but also protect the data from this account? One possibility could be to change the permissions on the data after it is copied to prevent deletion/interference, although I'm just making this up. Is there a standard practise for this?

you are viewing a single comment's thread
view the rest of the comments
[–] lIlIllIlIIIllIlIlII@lemmy.zip 18 points 9 hours ago (1 children)

Do pull backups instead of push backups: Backup server connects to local machine.

[–] non_burglar@lemmy.world 2 points 5 hours ago (2 children)

What's the rationale for this? Genuinely curious.

[–] bcnelson@lemmy.world 11 points 5 hours ago (1 children)

The reasoning is that your backup server should be more secure than production. Production has to have a bunch of stuff open in order to be useful and convenient. The backup server does not. It can be basically fully locked down.

[–] Onomatopoeia@lemmy.cafe 3 points 5 hours ago

To add - by doing pulls the backup server uses different credentials to run than the credentials used to perform pulls.

Backup server has it's own credentials database, machines being backed up have their own database. Backup service in backup server uses appropriate credentials from machine being backed up to access the data there (shares, etc). So credentials from compromised machine are unrelated to credentials for backup server.

And if backups are done properly (full on a schedule, daily incrementals, or something similar) you should be able to revert to a known-good state with minimal data loss.

[–] pgo_lemmy@feddit.it 3 points 4 hours ago* (last edited 2 hours ago)

If the main site gets compromised the credentials there must be considered lost and known to che attackers.

with a pull backup that's not an issue because the main site has no access to the remote system; it is a process on the remote site that has credentials to access the main site and not the other way around.

the remote system may ~~receive~~ retrieve a compromised copy of the data, but the attacker cannot tamper with previous backups so recovery is still possible.