cloning repository to untrusted server including keyfile still secure? #7949
-
I'm currently setting up my first borg backup repository and I'm unsure about how to handle the keyfile. I initalized my repository with Since my local machine and NAS are in the same network/close proximity I want to have an offsite backup. For this im renting a server from some company (The bottom line is I don't trust them and don't have full control over this external server). My plan is to clone my repository (on the NAS) to this external server every night. Now to my actual question: The repository on the NAS contains the
If I understand correctly its not a problem to have this keyfile on an untrusted server as long as the passphrase is kept secret, correct? Im unsure because the FAQ says |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Hmm, maybe the docs are a bit too alarming there. The The key is encrypted, so having only the key is not useful, you can only decrypt it with the passphrase. Of course you need to use a good, not guessable, long enough passphrase. |
Beta Was this translation helpful? Give feedback.
Hmm, maybe the docs are a bit too alarming there.
The
borg create
docs cover the key security (btw, there is also some stuff about copying repos in the FAQ).The key is encrypted, so having only the key is not useful, you can only decrypt it with the passphrase. Of course you need to use a good, not guessable, long enough passphrase.