Showing posts with label storage. Show all posts
Showing posts with label storage. Show all posts

Friday, February 21, 2014

If You Used This Secure Webmail Site, the FBI Has Your Inbox


While investigating a hosting company known for sheltering child porn last year the FBI incidentally seized the entire e-mail database of a popular anonymous webmail service called TorMail.
Now the FBI is tapping that vast trove of e-mail in unrelated investigations.
The bureau’s data windfall, seized from a company called Freedom Hosting, surfaced in court papers last week when prosecutors indicted a Florida man for allegedly selling counterfeit credit cards online. The filings show the FBI built its case in part by executing a search warrant on a Gmail account used by the counterfeiters, where they found that orders for forged cards were being sent to a TorMail e-mail account: “platplus@tormail.net.”
Acting on that lead in September, the FBI obtained a search warrant for the TorMail account, and then accessed it from the bureau’s own copy of “data and information from the TorMail e-mail server, including the content of TorMail e-mail accounts,” according to the complaint (.pdf) sworn out by U.S. Postal Inspector Eric Malecki.
The tactic suggests the FBI is adapting to the age of big-data with an NSA-style collect-everything approach, gathering information into a virtual lock box, and leaving it there until it can obtain specific authority to tap it later. There’s no indication that the FBI searched the trove for incriminating evidence before getting a warrant. But now that it has a copy of TorMail’s servers, the bureau can execute endless search warrants on a mail service that once boasted of being immune to spying.
“We have no information to give you or to respond to any subpoenas or court orders,” read TorMail’s homepage. “Do not bother contacting us for information on, or to view the contents of a TorMail user inbox, you will be ignored.”
In another e-mail case, the FBI last year won a court order compelling secure e-mail provider Lavabit to turn over the master encryption keys for its website, which would have given agents the technical ability to spy on all of Lavabit’s 400,000 users – though the government said it was interested only in one. (Rather than comply, Lavabit shut down and is appealing the surveillance order).
TorMail was the webmail provider of choice for denizens of the so-called Darknet of anonymous and encrypted websites and services, making the FBI’s cache extraordinarily valuable. The affair also sheds a little more light on the already-strange story of the FBI’s broad attack on Freedom Hosting, once a key service provider for untraceable websites.


Freedom Hosting specialized in providing turnkey “Tor hidden service” sites — special sites, with addresses ending in .onion, that hide their geographic location behind layers of routing, and can be reached only over the Tor anonymity network. Tor hidden services are used by those seeking to evade surveillance or protect users’ privacy to an extraordinary degree – human rights groups and journalists as well as serious criminal elements.
By some estimates, Freedom Hosting backstopped fully half of all hidden services at the time it was shut down last year — TorMail among them. But it had a reputation for tolerating child pornography on its servers. In July, the FBI moved on the company and had the alleged operator, Eric Eoin Marques, arrested at his home in Ireland. The U.S. is now seeking his extradition for allegedly facilitating child porn on a massive scale; hearings are set to begin in Dublin this week.
According to the new document, the FBI obtained the data belonging to Freedom Hosting’s customers through a Mutual Legal Assistance request to France – where the company leased its servers – between July 22, 2013 and August 2 of last year.
That’s two days before all the sites hosted by Freedom Hosting , including TorMail, began serving an error message with hidden code embedded in the page, on August 4.
Security researchers dissected the code and found it exploited a security hole in Firefox to de-anonymize users with slightly outdated versions of Tor Browser Bundle, reporting back to a mysterious server in Northern Virginia. Though the FBI hasn’t commented (and declined to speak for this story), the malware’s behavior was consistent with the FBI’s spyware deployments, now known as a “Network Investigative Technique.”
No mass deployment of the FBI’s malware had ever before been spotted in the wild.
The attack through TorMail alarmed many in the Darknet, including the underground’s most notorious figure — Dread Pirate Roberts, the operator of the Silk Road drug forum, who took the unusual step of posting a warning on the Silk Road homepage. An analysis he wrote on the associated forum now seems prescient.
“I know that MANY people, vendors included, used TorMail,” he wrote. “You must think back through your TorMail usage and assume everything you wrote there and didn’t encrypt can be read by law enforcement at this point and take action accordingly. I personally did not use the service for anything important, and hopefully neither did any of you.” Two months later the FBI arrested San Francisco man Ross William Ulbricht as the alleged Silk Road operator.
The connection, if any, between the FBI obtaining Freedom Hosting’s data and apparently launching the malware campaign through TorMail and the other sites isn’t spelled out in the new document. The bureau could have had the cooperation of the French hosting company that Marques leased his servers from. Or it might have set up its own Tor hidden services using the private keys obtained from the seizure, which would allow it to adopt the same .onion addresses used by the original sites.
The French company also hasn’t been identified. But France’s largest hosting company, OVH, announced on July 29, in the middle of the FBI’s then-secret Freedom Hosting seizure, that it would no longer allow Tor software on its servers. A spokesman for the company says he can’t comment on specific cases, and declined to say whether Freedom Hosting was a customer.
“Wherever the data center is located, we conduct our activities in conformity with applicable laws, and as a hosting company, we obey search warrants or disclosure orders,” OVH spokesman Benjamin Bongoat told WIRED. “This is all we can say as we usually don’t make any comments on hot topics.” Report By News24r Team.

Friday, January 24, 2014

Who makes the most reliable hard drives?



A few months ago we asked and answered one of computing’s oldest questions: How long do hard drives actually last? That story missed one vital piece of information, though — who makes the most reliable hard drives? Well, we can now answer that question too.
Just like last time, this information comes from Backblaze, an all-you-can-eat online backup company. Backblaze currently has around 28,000 hard drives powered up and constantly spinning, storing a total of around 80,000 terabytes (80 petabytes) of user data. As you can imagine, it is very much in Backblaze’s interests to ensure that it buys reliable hard drives. Every time a drive fails, it takes considerable time and effort to pull the drive, slot in a new one, and rebuild the RAID array.

Which hard drive manufacturer is the most reliable?

Backblaze breaks down its data in two ways — by manufacturer, and by specific drive. The data is fairly complex, but we’ll try to break it down into morsels of easy-to-digest, actionable information. (Read: How a hard drive works.)
As of the end of December 2013, Backblaze had 12,765  Seagate drives, 12,956 Hitachi drives, and 2,838 Western Digital drives. These drives are not all the same age — some are almost four years old, while many were installed in the past year. The odd numbers are because Backblaze basically buys whatever drive offers the most competitive dollar-per-gigabyte ratio, with reliability being a secondary factor. For most of the last four years, Seagate and Hitachi have offered the best price-per-gig, with Western Digital Red drives only now becoming a viable option for Backblaze.




Hard drive annual failure rate, broken down by maker (Hitachi, Seagate, Western Digital) and size
As you can see from the graph above, Hitachi drives are by far the most reliable. Even though most of Backblaze’s Hitachi drives are now older than two years, they only have an annual failure rate of around 1%. The “annual failure rate” is the chance of a drive dying within a 12-month period. After three years of being powered up 24/7, 96.9% of Hitachi drives are still running.
Western Digital is slightly worse, but still impressive: After three years of operation, 94.8% of Western Digital drives are still running. Backblaze lists the annual failure rate of the WD drives at around 3% (I don’t think the numbers quite add up, but I could be wrong).
Seagate drives are not very reliable at all. As you can see in the second graph below, Seagate drives are fine for the first year, but failures quickly start building up after 18 months. By the end of the third year, just 73.5% of Backblaze’s Seagate drives are still running. This equates to an annual failure rate of 8-9%.



Hard drive failure rate, plotted by month
In Backblaze’s words: “If the price were right, we would be buying nothing but Hitachi drives. They have been rock solid, and have had a remarkably low failure rate.”

Which single hard drive is the most reliable? (And which is the least?)

In general, then, if you want a reliable hard drive you should go for a Hitachi or Western Digital. If you’re looking for a specific drive model that has good longevity, the numbers break down interestingly.
The two best drives, with 0.9% annual failure rate over more than two years, are the Hitachi GST Deskstar 5K3000, and Hitachi Deskstar 7K3000. Get one of these drives and you’re almost guaranteed (97-98%) to make it through three years without a dead drive. If you want a 4TB drive, the Hitachi Deskstar 5K4000 is your best bet — it has a slightly higher failure rate, but still below WD and Seagate’s offerings.
As far as poor reliability goes, Seagate has some nasty offenders. The 1.5TB Seagate Barracuda 7200 (an old drive now) has a very high chance of failing after three or four years. Even the newer 3TB Seagate Barracuda has a pretty high failure rate, at 9.8% per year.
Backblaze also notes that some drives (the Western Digital Green 3TB and Seagate Barracuda LP 2TB) start producing errors as soon as they’re slotted into a storage pod. They think this is due to the large amounts of vibration caused by thousands of other hard drives. (They also think that their aggressive spin-down setting, which is ostensibly to save power, causes a lot of wear to the drive.)
Hit up Backblaze’s website for a full list of hard drives and their statistics.

Samsung and Toshiba

Unfortunately, Backblaze doesn’t have a statistically significant number of Samsung or Toshiba drives installed. Even so, because Samsung’s hard drive division was acquired by Seagate in 2011, it’s hard to say if an older, pre-acquisition Samsung drive would be more or less reliable than a post-acquisition drive. Toshiba/Fujitsu still have a reasonable wedge (~10%) of the market share pie, but unfortunately we’ll have to wait for another study to see how they compare to Seagate, Western Digital, and Hitachi.
On the topic of acquisitions, you may also remember that Western Digital acquired Hitachi GST almost two years ago. If we compare Hitachi drives from before and after the acquisition, the annual failure rate seems to stay the same (around 1%). It would seem that Western Digital and Hitachi have the reliable hard drive business sewn up — and this is before we’ve had a chance to see what WD/HGST’s helium-filled hard drive can do!