Live data from Hacker News

Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

backblaze.com

131–140 of 190 posts

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#131
post #127

Earlier quoted context omitted.

Theoretically, yes, it can happen. Realistically, the chance of a tornado taking out the Swedish datacenter built inside a former nuclear bunker under 100ft of granite bedrock is so small that it probably doesn't affect the number of 9's that you can claim.

Sadly not even Swedish nuclear bunkers are safe from disaster: https://www.theguardian.com/environment/2017/may/19/arctic-s... > Arctic stronghold of world’s seeds flooded after permafrost melts > It was designed as an impregnable deep-freeze to protect the world’s most precious seeds from any global disaster and ensure humanity’s food supply forever. But the Global Seed Vault, buried in a mountain deep inside the Ar…

Not a tornado, though.

> There are always unforeseen and unforeseeable risks associated with any location. You can mitigate them but you can't claim X number of 9s for a single physical datacenter.

What is X, here? I'm pretty sure I can claim 99% for a single datacenter.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#132

Earlier quoted context omitted.

Sadly not even Swedish nuclear bunkers are safe from disaster: https://www.theguardian.com/environment/2017/may/19/arctic-s... > Arctic stronghold of world’s seeds flooded after permafrost melts > It was designed as an impregnable deep-freeze to protect the world’s most precious seeds from any global disaster and ensure humanity’s food supply forever. But the Global Seed Vault, buried in a mountain deep inside the Ar…

Not a tornado, though. > There are always unforeseen and unforeseeable risks associated with any location. You can mitigate them but you can't claim X number of 9s for a single physical datacenter. What is X, here? I'm pretty sure I can claim 99% for a single datacenter.

hell, I can probably do a solid 9% just visiting the local coffee shop twice a week.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#133

Earlier quoted context omitted.

Sadly not even Swedish nuclear bunkers are safe from disaster: https://www.theguardian.com/environment/2017/may/19/arctic-s... > Arctic stronghold of world’s seeds flooded after permafrost melts > It was designed as an impregnable deep-freeze to protect the world’s most precious seeds from any global disaster and ensure humanity’s food supply forever. But the Global Seed Vault, buried in a mountain deep inside the Ar…

Not a tornado, though. > There are always unforeseen and unforeseeable risks associated with any location. You can mitigate them but you can't claim X number of 9s for a single physical datacenter. What is X, here? I'm pretty sure I can claim 99% for a single datacenter.

What I meant is you can't necessarily amortize loss in the event of a localized catastrophe. Failure modes in a single location are by definition not always statistically independent. You could have 99.99999% durability for 20 years, but if something happens to the datacenter that causes total loss, you're SOL. Geographical redundancy vastly reduces the risk of freak occurrences that you can't predict.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#134
post #116

Earlier quoted context omitted.

For a consumer the cheapest and easiest way to backup important documents or files is to encrypt it and store it across multiple storage providers, e.g. Dropbox and Google Drive. They usually give you a reasonable amount of free storage, and it's unlikely all accounts would be terminated or locked at the same time. And of course, you should always have your local backups as well.

Assume you want access to files over the next 20 years. What are the odds Google will have bought Dropbox in that time; and what are the odds an automated system monitor at Google ad words will have disabled your Google account in that time span? Replace with Amazon and/or crashplan as appropriate..

Backblaze suggests a “3-2-1” backup strategy. You should always have at least one backup on site. If a remote backup becomes inaccessible, you could move over to another remote access provider.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#135
This article supposes that a meteor impact is more likely than disaster that renders northern California (their only data centers are in Oakland and Sacramento AFAIK) without power or civil order within ten million years.

As someone else pointed out, it’s overly simplistic. They’re a great low-cost alternative to S3, sure. But keep a backup on another continent if you need your data 100 years from now.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#136

It's a really nice blog post but coming from Backblaze, it would have been nice if they wrote it _after_ bringing the Phoenix DC fully online. When Amazon or Google say 11 9s, I can believe it but Backblaze still only has a single datacenter for most data. All it takes is an earthquake.

Or an overzealous prosecutor.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#137

why calculate poisson and binomial when both are ultimately gaussian?

They're not ultimately gaussian. :) The normal distribution is continuous and has unbounded support whilst neither the binomial or Poisson ate cts and unbounded.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#138
post #72

Earlier quoted context omitted.

Nope. They aren’t even in the same city. For example, each of the AZs in us-west-2 are separated by about 50-60 miles. This doesn’t list all the locations, but is a good map to get an idea: https://www.google.com/maps/d/u/0/viewer?ll=50.9584270000000...

That map is incorrect: us-west-2a, 2b and 2c are not static names for the AZs. Every user gets their own mapping of which physical location is a, which one is b and which one is c. My us-west-2a may be your us-west-2c. They are not the same.

Yes, I know they pseudo randomize the allocations. That is irrelevant to my core point, that each AZ is not just separate networks in the same building or even adjacent buildings, but rather they are truly isolated by a non-insignificant distance of somewhere around 50mi on average.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#139
The Backblaze blog post points to Amazon's CTO (Werner Vogel)'s blog post, in which he states that "...These techniques allow us to design our service for 99.999999999% durability."

(side note: Werner is a great person)

Unfortunately, there is a difference, a huge difference, between a system "designed" for 11 9s of durability, and a system "offering" 11 9s of durability.

I wish Backblaze, or Amazon, or anybody else, would clarify durability using very honest terms.

An example?

"This system offers X 9s of durability over a period of one year, on average. This is a technical paper that describes how we tested that durability", followed by measurements and test specifics.

Any other claim has much less value to me.

Re: Backblaze Durability Is Eleven 9s – And Why It Doesn’t Matter

#140
post #84

This analysis is simplistic. Correlated failures are common in drives. That could be a power surge taking out a whole rack, a firmware bug in the drives making them stop working in the year 2038, an errant software engineer reformatting the wrong thing, etc. When calculating your chance of failure, you have to include that, or your result is bogus. Eg. Model A of drive has a failure rate of 1% per year, but when fail…

> Correlated failures are common in drives. This is why, when I was building DIY arrays for startups (around the same time Backblaze published their first pod design [1]), I went through the extra effort of sourcing disks from as many different vendors as possible. Although it was somewhat more time consuming and limited how good a price I could get and how fast the delivery could be, it meant that, for any given dis…

I've been doing a poor man's version of this for home videos using 3 hard drives and rsync. It's easy to replace a drive and they are not likely to go out at the same time. But one thing that bugs me is that unless the drive fails hard (e.g. noticed by SMART or unable to read at all) how do I know the data on the drive is not corrupted without reading it? Are there best practices to continuously compare the replicas in the background? Does that impact durability of the drives?
Post reply on HN