Hacker Newsnew | past | comments | ask | show | jobs | submit | more nithssh's commentslogin

Very enlightening piece on how corpo sponsorship of OSS work. Thanks to the author for writing this.


There are a lot of reasons why just making a copy of the files you need to another FS is not sufficient as a backup, clearly this is one of those. We need more checks to ensure integrity and robustness.

BorgBackup is clearly quite good as an option.


> BorgBackup is clearly quite good as an option.

After one enables rsync with checksums, doesn't Borg have the same issue? I believe Borg needs to do the same rolling checksum over all the data, now, as well?

ZFS sounds like the better option -- just take the last local snapshot transaction, then compare to the transaction of the last sent snapshot, and send everything in between.

And the problem re: Borg and rsync isn't just the cost of reading back and checksumming the data -- for 100,000s of small files (1000s of home directories on spinning rust), it is the speed of those many metadata ops too.


As with rsync borg does not read files if their timestamp/length do not change since the last backup. And for million files on modern SSD it takes just few seconds to read their metadata.


> As with rsync borg does not read files if their timestamp/length do not change since the last backup.

...but isn't that the problem described in the article? If that is the case, Borg would seem to the worst of all possible worlds, because now one can't count on its checksums?


If one worries about bitrot, the backup tools are not good place to detect that. Using a filesystem with native checksums is the way to go.

If one worries about silent file modifications that alters content but keep timestamp and length, then this sounds like malware and, as such, the backup tools are not the right tool to deal with that.


> If one worries about bitrot, the backup tools are not good place to detect that. Using a filesystem with native checksums is the way to go.

Agreed. But I think that elides the point of the article which was "I worry about backing up all my data with my userspace tool."

As noted above, Borg and rsync seem to fail here, because it's wild how much the metadata can screw with you.

> If one worries about silent file modifications that alters content but keep timestamp and length, then this sounds like malware and, as such, the backup tools are not the right tool to deal with that.

Seen this happen all the time in non-malware situations, in what we might call broken software situations, where your packaging software or your update app tinker with mtimes.

I develop an app, httm, which prints the size, date and corresponding locations of available unique versions of files residing on snapshots. And -- this makes it quite effective at proving how often this can happen on Ubuntu/Debian:

    > httm -n --dedup-by=contents /usr/bin/ounce | wc -l
    3
    > httm -n --dedup-by=metadata /usr/bin/ounce | wc -l
    30


The latter type case is what the article is talking about though. At the same time, as the article also discusses, it's unlikely to have actually been caused by malware vs something like a poorly packaged update.

Backup tools should deal with file changes lacking corresponding metadata changes despite it being more convenient to say the system should just always work ideally. At the end of the day the goal of a backup tool is to backup the data, not to skip some of the data because it's faster.


Amen!


This is great for web developers who have to manually write multi-browser compliant code. Fat frameworks might take care of the cross compat stuff, but for those raw dogging, this will be good.


Running containers inside VMs in multitenant scenarios is so common that Google though of inventing gVisor which you can think of as a highly paravirtualized guest OS that is lighter than a full VM but still based on similar virtualization principles for isolation.


I read the first line and expected LLM spam, but I was wrong. Thanks for the detailed comparison.


Thanks, when I read it know it really sounds like LLM :)

Say hello to vermadenGPT :]


Isn't Kerala's economy held up by remittances and duct tape?


Land of the free after all


Money is the only free thing in America

so an American citizen’s freedom is directly correlated with their net worth in USA dollars


Your second sentence is pretty much true everywhere, just the strength of the correlation varies. Even in places that try to be even handed the simple fact that a wealthy person has more resources makes them freer.


[flagged]


Maybe the point is that the trait "supporting Hamas" will be judged by AI.


The article is pretty scant on details in terms of how the judgment would be made but using AI to process for an initial review followed by a final human review seems like a slam dunk choice imo


Is there going to be a review of the false positive and false negative rates? Will the humans review negative and positive results equally well? Will any of the process be transparent?

Exactly what will the humans review?


Why are you asking me? I already said this article that half of HN is raging at is scant on any detail. If you don’t know the answers to these questions, which would make sense because this article basically says nothing, and it’s important to you you should probably look into it.


Is this about the security of the USA or the security of our greatest ally?


I would be interested to hear how expelling Hamas supporters from the United States is at all beneficial to France.


My reaction to this comment is surely Canada or Mexico is the greatest ally of the USA. But, indeed, that may no longer be true under Trump.


I still think it’s France. There’s a good reason for so many cities being named Lafayette


Of course saying "stop the genocide" will be interpreted as supporting hamas.

Question is, are you ok with this interpretation or not?


It's quite interesting how when americans wake up comments like that go from upvoted to downvoted.


Maybe it’s downvoted because it’s an unsupported assumption you made and Americans are uniquely capable of recognizing that?


I notice how you reply to this but not to where you stand. I guess we know where you stand.


I don’t engage with people who make unsupported statements with rhetorical aims on their own terms.


Yes I'm on the "against genocides" team.


They have no problem with US holocaust deniers.


They certainly have no problem sending billions of tax payer money and sign missiles to m*rder children.

I think the point here is to prime the public for this discriminatory use of AI. Today it's "bad hamas", tomorrow it can be whatever the current government deems "bad". And by then, it'll be too late.


You can say “murder” here. This isn’t TikTok


Makes sense considering Valve has maintained that kernel level AC is not required and has not included one in their own games, but let's be honest, unfortunately you have to often wonder if your enemy is having a good day or if he's hacking in CS but not so in valorant for a reason.


I'm also hearing a bunch of grumblings and speculation that Valve is developing a non kernel level anti cheat.


They have VAC and the newer version that they promised would save CS2 hasn't exactly changed much from CSGO days in terms of results.

I would love for Valve to prove it is possible but so far they haven't shown it can be done without leaving a bad experience for legit players (due to delayed ban waves, etc) despite the repeated claims.


I wonder how explicit and clear they were about the intended purpose of these vouchers. I can see myself saying fck it and using it however I feel without thinking much since it seems insignificant, unless they make a deal of it.


This is a super weirdly written article that reads like something I would expect to be written about Xi and China in a Chinese publication.


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: