İçeriğe atla

Final Unicourse'tan Çalış, Yüksek Notu Garantile!

%25 İndirim Kodu: FRM25
Yükleniyor...
Dersi İzle
GÖRÜNTÜLEYENLER
+36
Premium Özellik
Bu konuyu kimlerin görüntülediğini görmek için Premium üyelik gerekir.
Premium'a Geç

Vizesine Unicourse'tan Çalış, Yüksek Notu Garantile!

A B C D Çıkmış Sorular Formül Kağıtları Konu Anlatımı Sınav İpuçları Örnek Sınav
Dersi İzle
Red Bull Basement
SPONSORLU ETKİNLİK

Fikrini Gerçeğe Dönüştür

Projeni dünyaya göstermek için sahne hazır. Red Bull Basement başvuruları açık.

Başvurunu Yap

🎉 Foruma Yeni Özellik Geldi!

Sizin için PDF toollarını getirdik!

How much data is retreivable form one disk in a raid 5 array

techsupport
6 4 0
  • If i would, hypothetically, have a few different drives in a raid5 array in different physical locations, and one was seized, how much data could be reconstructed from that drive?

    (I was reading about A/I and their R* system a bit, and this semi-related idea came to mind)

  • If i would, hypothetically, have a few different drives in a raid5 array in different physical locations, and one was seized, how much data could be reconstructed from that drive?

    (I was reading about A/I and their R* system a bit, and this semi-related idea came to mind)

    That would depend a lot on the configuration.

    What filesystem was used?

    How full was the array?

    Did you configure encryption?

    What kind of data was stored on the array?

    To be frank, I have no idea about this, but all of the above are things that affect the raid array.

    In cases like this, you need to plan for the worst, so you are prepared for it if it happens.

  • If i would, hypothetically, have a few different drives in a raid5 array in different physical locations, and one was seized, how much data could be reconstructed from that drive?

    (I was reading about A/I and their R* system a bit, and this semi-related idea came to mind)

    Doesn't RAID5 just distribute stripes of the data over the disks plus parity? I think they'd get random stripes of your data. If your stripe size is 128kb, they'd get a 128k chunk of an image here, a part of another image there... Text doesn't use a lot of space so there might be a long text or several emails within some stripe... If you're lucky that was just your spamfolder... If they're lucky, it's the text document containing your master password list plus your confession to all the crimes committed... Chances are they seize the disk with that specific data on it. Or maybe they happen to take one of the other ones. Could be on any of them.
    Larger files get distributed over the disks due to striping. Depends on the file type... Maybe parts of large file can be used against you, maybe they can't.

  • That would depend a lot on the configuration.

    What filesystem was used?

    How full was the array?

    Did you configure encryption?

    What kind of data was stored on the array?

    To be frank, I have no idea about this, but all of the above are things that affect the raid array.

    In cases like this, you need to plan for the worst, so you are prepared for it if it happens.

    It would probably be an ext4 fs and lets say the array is 20% used.

    In any real world application i would have encryption, but for the sake of this hypothetical, i don't.

    And about the data, it would probably be a mixture of big and small files like text files, videos and images.

  • Doesn't RAID5 just distribute stripes of the data over the disks plus parity? I think they'd get random stripes of your data. If your stripe size is 128kb, they'd get a 128k chunk of an image here, a part of another image there... Text doesn't use a lot of space so there might be a long text or several emails within some stripe... If you're lucky that was just your spamfolder... If they're lucky, it's the text document containing your master password list plus your confession to all the crimes committed... Chances are they seize the disk with that specific data on it. Or maybe they happen to take one of the other ones. Could be on any of them.
    Larger files get distributed over the disks due to striping. Depends on the file type... Maybe parts of large file can be used against you, maybe they can't.

    But how hard is it to reconstruct an image without the file headers? I get that text files are toast if they aren't encrypted, but wouldn't any other filetype that is not human-readable be very hard to retreive?

  • If i would, hypothetically, have a few different drives in a raid5 array in different physical locations, and one was seized, how much data could be reconstructed from that drive?

    (I was reading about A/I and their R* system a bit, and this semi-related idea came to mind)

    If someone is coming physically for your stuff, They wont just take a drive, they will take the whole thing so they will have access to the whole thing.

    This is where drive encryption comes in so when they power it back on it asks for the drive decryption key, of some kind of intermediate key to get the actual key from the TPM.

    There is a defcon talk about anti-forensic and anti anti forensic mechanisms you can use to watch to make breaking your system take longer.


Önerilen Başlıklar

8

Çevrimiçi

8.8k

Kullanıcı

1.9k

Konu

3.7k

İleti