Glenn Buckholz
Cadet
- Joined
- Apr 3, 2015
- Messages
- 8
Hey all. I've been a FreeNAS user for over a year now and I wanted to re-enforce a lesson learned. Back up your encryption keys and test them monthly.
This is my sob story, and no FreeNAS functions nearly flawlessly, this was all my fault.
I created a highly redundant raid2z volume. Since I have work information on here I encrypted it. Since the storage space was so large I put personal stuff there too. Then I dutifully placed the recovery keys on a USB stick and on a safe locally accessable place and went on my merry way for a year, until yesterday. A series of unfortunate events caused me to loose 4TB of data, work and personal.
1. My passpharse got deleted from my password vault.
2. I accidentlly deleted my local recovery keys freeing up space.
3. My failsafe USB drive got.... repurposed.
Now, unless I can guess my passphrase its all gone. I did learn some things here though and I thought I'd share.
1. If you have a need for encryption make sure you encrypt only what is necessary.
-If you loose you keys you are only out a minimal set of information, albit important information
2. Test using your backup recovery keys once a month and master key with passphrase.
-set a google calendar reminder. One test would have saved me heartache and it takes maybe 10 minutes.
3. I downloaded the master key not the recovery key because I was careless.
-Minutes before my ill fated reboot I verified that I re-downloaded what I though were the keys but it was the master key that needed the passphrase I didn't have, not the recovery key... make sure you see _recovery in the downloaded file name. This gave me a false sense of security and was the most frustrating part of this escapade.
4. For must have stuff use offsite backups. My photos, the most irreplaceable things I have were backed up in S3 using the s3 plugin.
-Although I lost alot, I at least have the most important things restoreing right now. The money I spent on 200GB of s3 storeage is well worth it.
Learn from my mistakes everyone. Happy storage all.
This is my sob story, and no FreeNAS functions nearly flawlessly, this was all my fault.
I created a highly redundant raid2z volume. Since I have work information on here I encrypted it. Since the storage space was so large I put personal stuff there too. Then I dutifully placed the recovery keys on a USB stick and on a safe locally accessable place and went on my merry way for a year, until yesterday. A series of unfortunate events caused me to loose 4TB of data, work and personal.
1. My passpharse got deleted from my password vault.
2. I accidentlly deleted my local recovery keys freeing up space.
3. My failsafe USB drive got.... repurposed.
Now, unless I can guess my passphrase its all gone. I did learn some things here though and I thought I'd share.
1. If you have a need for encryption make sure you encrypt only what is necessary.
-If you loose you keys you are only out a minimal set of information, albit important information
2. Test using your backup recovery keys once a month and master key with passphrase.
-set a google calendar reminder. One test would have saved me heartache and it takes maybe 10 minutes.
3. I downloaded the master key not the recovery key because I was careless.
-Minutes before my ill fated reboot I verified that I re-downloaded what I though were the keys but it was the master key that needed the passphrase I didn't have, not the recovery key... make sure you see _recovery in the downloaded file name. This gave me a false sense of security and was the most frustrating part of this escapade.
4. For must have stuff use offsite backups. My photos, the most irreplaceable things I have were backed up in S3 using the s3 plugin.
-Although I lost alot, I at least have the most important things restoreing right now. The money I spent on 200GB of s3 storeage is well worth it.
Learn from my mistakes everyone. Happy storage all.