Comprehensive data protection for all workloads
Post Reply
ian0x0r
Veeam Vanguard
Posts: 235
Liked: 48 times
Joined: Nov 11, 2010 11:53 am
Full Name: Ian Sanderson
Location: UK
Contact:

The word from Gostev 10th Sep 2018

Post by ian0x0r » 1 person likes this post

Morning all,

A very informative word from Gostev today about ReFS adoption and where the reported issues usually lie. What piqued my interest though was whether or not the sample set of 13500 sets of debug log data was voluntarily submitted to Veeam as part of a support case OR if Veeam has some kind of anonymous phone home capability (I don't think it does)?

Any insight into this would be greatly appreciated :)

Thanks,

Ian
Check out my blog at www.snurf.co.uk :D
Gostev
Chief Product Officer
Posts: 31561
Liked: 6725 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: The word from Gostev 10th Sep 2018

Post by Gostev »

ian0x0r wrote:What piqued my interest though was whether or not the sample set of 13500 sets of debug log data was voluntarily submitted to Veeam as part of a support case
This. We don't have any sort of phone home for debug logs, and not planning to be introducing one.
ian0x0r
Veeam Vanguard
Posts: 235
Liked: 48 times
Joined: Nov 11, 2010 11:53 am
Full Name: Ian Sanderson
Location: UK
Contact:

Re: The word from Gostev 10th Sep 2018

Post by ian0x0r »

Thanks for the quick response Anton :)

Ian
Check out my blog at www.snurf.co.uk :D
k00laid
Veeam Vanguard
Posts: 222
Liked: 51 times
Joined: Jan 13, 2011 5:42 pm
Full Name: Jim Jones
Location: Hurricane, WV
Contact:

Re: The word from Gostev 10th Sep 2018

Post by k00laid »

Is the data anonymized in the process of doing the data mining? While I trust Veeam with my data having VM and job names show up in a paste bin in the case of something silly happen would be awkward.
Jim Jones, Sr. Product Infrastructure Architect @iland / @1111systems, Veeam Vanguard
Rick.Vanover
Veeam Software
Posts: 708
Liked: 167 times
Joined: Nov 30, 2010 3:19 pm
Full Name: Rick Vanover
Location: Columbus, Ohio USA
Contact:

Re: The word from Gostev 10th Sep 2018

Post by Rick.Vanover »

Guys there absolutely is no dial home. In fact, most B&R servers are off the Internet - that's a good practice too.
Rick.Vanover
Veeam Software
Posts: 708
Liked: 167 times
Joined: Nov 30, 2010 3:19 pm
Full Name: Rick Vanover
Location: Columbus, Ohio USA
Contact:

Re: The word from Gostev 10th Sep 2018

Post by Rick.Vanover »

The other thing I would add is that now with SO MANY customers - we have some very good aggregated views on data, additionally - there are corner cases in the corner of the corner. LOL
Gostev
Chief Product Officer
Posts: 31561
Liked: 6725 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: The word from Gostev 10th Sep 2018

Post by Gostev »

k00laid wrote:Is the data anonymized in the process of doing the data mining? While I trust Veeam with my data having VM and job names show up in a paste bin in the case of something silly happen would be awkward.
I don't really understand your question, perhaps you're thinking some other type of reports? May be you can give me an example of what kind of big data report output you have in mind that may require anonymization?

Because at least in our case, it's all about collecting numbers for statistics purposes, for example - the number of ESXi hosts of certain version that we consider dropping. And even if I imagine some nonsense report that would actually tie up to a VM name or job name, for the results to be actionable in case of big data, it would have to be something like "What percent of customers have a VM named myCriticalVM", and the output of this report will still be the number (or percent) of deployments in the data set. So, there's nothing to anonymize here further?

In other words, "anonymization" of big data into numbers is specifically what makes it usable and actionable.
dellock6
VeeaMVP
Posts: 6139
Liked: 1932 times
Joined: Jul 26, 2009 3:39 pm
Full Name: Luca Dell'Oca
Location: Varese, Italy
Contact:

Re: The word from Gostev 10th Sep 2018

Post by dellock6 »

Rick.Vanover wrote:Guys there absolutely is no dial home. In fact, most B&R servers are off the Internet - that's a good practice too.
Not if you want license auto-update :wink:
Luca Dell'Oca
Principal EMEA Cloud Architect @ Veeam Software

@dellock6
https://www.virtualtothecore.com/
vExpert 2011 -> 2022
Veeam VMCE #1
AlexLeadingEdge
Veteran
Posts: 456
Liked: 58 times
Joined: Dec 14, 2015 9:42 pm
Contact:

Re: The word from Gostev 10th Sep 2018

Post by AlexLeadingEdge »

dellock6 wrote:Not if you want license auto-update :wink:
And remote administration...
Gostev
Chief Product Officer
Posts: 31561
Liked: 6725 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: The word from Gostev 10th Sep 2018

Post by Gostev »

In the environments where security is important, remote administration is usually done through a jumpbox, so the backup server itself is never connected to the Internet.
nmdange
Veteran
Posts: 527
Liked: 142 times
Joined: Aug 20, 2015 9:30 pm
Contact:

Re: The word from Gostev 10th Sep 2018

Post by nmdange »

For real security, you should be using a Privileged Access Workstation. Jump boxes are not really all that useful, since the computer you are typing your password on and also using to browse the internet could be much more easily compromised. https://docs.microsoft.com/en-us/window ... rkstations

Not really relevant to this discussion, but ever since I learned about PAW, it's been my mission to educate people on the value of using them for security :D
Gostev
Chief Product Officer
Posts: 31561
Liked: 6725 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: The word from Gostev 10th Sep 2018

Post by Gostev »

I mean, jump box is the name of the concept. PAW is one of the possible implementations of a jump box for Windows shops (instead of the classic Windows Server with RDS). For example, in Unix world a typical jump box is a hardened Unix (or Unix-like) machine configured with SSH and a local firewall.
nmdange
Veteran
Posts: 527
Liked: 142 times
Joined: Aug 20, 2015 9:30 pm
Contact:

Re: The word from Gostev 10th Sep 2018

Post by nmdange » 1 person likes this post

The key point of PAW and not a jump box is that the physical device an administrator is using must be hardened. If you use that device for other purposes like e-mail, web browsing, etc., or if it's accessible to lower privilege user accounts (desktop support techs, or other domain users) then there is a risk the device you use being compromised and your administrator credentials being captured by a keylogger or other malware. In the past, this often meant having two separate laptops/desktops, but now you can run VMs locally to accomplish the same goal. But the important part is that the untrusted/non-admin workload (e-mail, web browsing), takes place in a VM. The Administration workload can be on the physical device or in a second VM. A jump box could still be used, but you must secure the physical endpoint.
stubbint
Service Provider
Posts: 7
Liked: 2 times
Joined: Oct 13, 2011 2:14 pm
Full Name: Trevor Stubbins
Contact:

Re: The word from Gostev 10th Sep 2018

Post by stubbint » 1 person likes this post

AlexLeadingEdge wrote: Sep 13, 2018 10:11 pm And remote administration...
And access to a Cloud Repository.... :)
Post Reply

Who is online

Users browsing this forum: Google [Bot] and 135 guests