Live data from Hacker News

Backblaze B2 Cloud Storage

backblaze.com

171–180 of 237 posts

Re: Backblaze B2 Cloud Storage

#171
post #147

Earlier quoted context omitted.

> They require a SHA1 hash when uploading objects. This is probably overkill over a cheaper CRC. Having been on the receiving end of entirely too many corrupted files in my life, I strongly approve of their use of a hash that's been standardized and fast for decades and remains cryptographically strong. "But fast" if you fail to store it isn't very helpful. TCP has a CRC too. We're wallpapering over it with better on…

Using a hash or CRC here is totally necessary. Often times CRCs in TCP fail due to corruption outside the network stack. Having an end to end check will catch, say, memory bit flips and such after data comes off the wire. But there is no call for a cryptographic hash here. This isn't being used as any sort of ID or to verify integrity outside of corruption.

No, it's pretty much totally unnecessary.

The API works on top of TLS, which already includes cryptographic authentication of all data (usually via SHA-1/2 HMAC or AES-GCM).

The hash would be computed at the client right after reading from disk and right before TLS enryption, and since they seem to terminate TLS at the storage server it would be computed right after TLS decryption and right before storage, so it doesn't seem to provide any gain.

I think they should just remove it, or at least make it optional.

Re: Backblaze B2 Cloud Storage

#172
post #14

Earlier quoted context omitted.

Please go into detail about how failures are detected and handled – e.g. how often is the archive scrubbed, will bitrot be detected on access, etc. Those details are really important for comparing services.

Does AWS provide this info for S3? I believe they do not, and only provide a percentage of durability maintained.

I'm definitely asking because those are questions to ask every vendor. Don't forget, also, that this space includes things like running your own services using Swift, Ceph, etc. so it's certainly possible to answer definitively those questions for at least some other options.

Re: Backblaze B2 Cloud Storage

#173
Are there any plans to add application hosting along with this offering? Specifically, it could be useful to have a shim application that has direct access to the data without traversing the Internet, to minimize what needs to be transferred. For example, if used for a backup application, each day's incremental delta may be in one archive, but a periodic operation would be to move files from one archive to another. Or a full system restore may be pulling some data out of multiple archives, and a "shim" app (running within Backblaze's data center) would eliminate unnecessary transfers out.

Re: Backblaze B2 Cloud Storage

#174

For context, OVH offers object storage with 3x replication for $.01/GB [1]. [1] https://www.runabove.com/cloud-storage.xml

It is certainly interesting how OVH undercuts the competition by quite a large margin in everything. We use them for dedicated servers, but I wonder why they're not as well known as AWS...

For me, there's a combination of reasons.

First, they weren't in North America until recently. Having a server in France means high ping times for me and latency for the vast majority of my visitors. OVH started operations in Québec in 2013. So they've had less than three years to establish themselves. EC2 is 9 years old.

Second, it's hard to figure out what to buy. With EC2, they're all Xen instances and you decide on the right CPU/RAM configuration. DigitalOcean, Linode, Vultr, etc. all are easy. With OVH, what am I supposed to buy? Do I want a dedicated server or an infrastructure dedicated server? And then if I click for dedicated, I need to choose from Hosting, Enterprise, Infrastructure, Storage, Custom, or Game. I know computers - tell me the processor, RAM, and storage without breaking it into categories. So, I go with Hosting and half of the options are for "Delivery from September 30". Ok, that's more than a week out. Maybe I want more flexibility like hourly billing on VPSs. I can go to Cloud -> VPS. And now I can choose SSD or Cloud with different prices. Why is the SSD so much cheaper? $3.50 vs $9 and they're both 1 core, 2GB of RAM, 100Mbps network link KVM boxes. Then I wonder if these are the same things as the RunAbove labs vs regular. The labs ones shared the processor cores, but this seems to indicate that both don't have the noisy neighbor problem. So I check RunAbove. Wow, everything has changed. Looks like they don't offer the SSD of Ceph instances anymore, but they have SATA backed instances. So, they're running all sorts of different combinations. And should I be looking into Kimsufi or SYS brands? Do they still exist? What if I want object storage. Ok, the US site takes me to RunAbove which tells me that it's now part of OVH proper which brings me to their UK site with apparently no way of loading it on the American site. Compare that to DigitalOcean where you just get a very simple, "here are the plans, there's no complex stuff with weird names or categories, buy what you need." Even Vultr manages simple with SSD VPS, SATA VPS, and Dedicated Cloud. Perfect. Most likely I want the SSD VPS, but maybe I need more storage or maybe I want metal servers sold to me like cloud servers. Easy.

And to be fair, OVH used to be a lot more complicated and a lot worse. It looks like they're streamlining a ton. But they should still simplify a lot more.

Third, OVH is terrible at marketing. I want to define what I mean by marketing. DigitalOcean is a king of marketing. You go to their site and you see brief comments from the creator of jQuery, the creator of RailsCasts, the creator of Redis, and a Rails core member. You might not use those technologies or even like them, but you recognise that DigitalOcean can't be total crap given that these are people with options and a reasonable amount of taste. DigitalOcean sponsors hackathons like woah. Giving students a dozen or so dollars in credit makes them well-known and an easy service to try. DigitalOcean's site inspires confidence in its simplicity. You don't feel like there's some hidden thing because it's just simple plans that increase rather linearly. Finally, try searching for VPS + some tech term. "VPS Ansible" has a DigitalOcean blog article as #3. "VPS elasticsearch" has DO with the top two spots. The point is that you see that and it's an indication that they're part of the community (supporting some free content) and kinda get it.

OVH, on the other hand, inspires none of those good feelings. OVH has a generic site that you can't tell apart from other generic sites. It has the kind of "throw everything at the user and see what sticks" design that I don't think users want. We want DigitalOcean to say "this! this is good!". OVH is like, we have a lot of different things and someone has written "enterprise" or "cloud" on some of them without really indicating how some options are more "enterprise" or "cloud". And there are stock images of network switches and RAM and such like a pizza place that has a stock picture of a pizza on their take-away menu that isn't their pizza. Do they get it?

I really wish OVH well. More providers means downward pressure on pricing which is good for me. I mean, 2GB of RAM VPS for $3.50? Awesome! Glad to see that graduate from RunAbove. But OVH still has a ways to go. Lots of the time you have to wait for servers. If I want a dedicated SSD box, they're quoting a 10 day wait for all except one model. The entire "hosting" range has quotes of 3-12+ days. "Enterprise" has one box for 120 second provision, two that are 3 days out, and two that are 10 days out. It seems like OVH is a place to get a good deal if you're willing to deal with complicated process, waiting for a box, and them switching things up on you. But maybe OVH is stabalizing. I'm hoping their VPS offering will be a lot more stable than it has been. Seems like they're cutting down on using alternative brands like SYS and Kimsufi.

I can see OVH being a good company, but it's no surprise to me that they aren't as well known as AWS.

Re: Backblaze B2 Cloud Storage

#175

Are there any plans to add application hosting along with this offering? Specifically, it could be useful to have a shim application that has direct access to the data without traversing the Internet, to minimize what needs to be transferred. For example, if used for a backup application, each day's incremental delta may be in one archive, but a periodic operation would be to move files from one archive to another. O…

Brian from Backblaze here. We'll add a LITTLE bit of app hosting support around this, but you won't be seeing a full blown EC2 type of product out of Backblaze for a while, realistically we don't have a large enough team to charge down that path and still do a great job at B2 and also our traditional online backup product that we still maintain.

What I'd really like in the short term is to do a deal with Amazon where we put a "virtual cross connect" from the Backblaze datacenter into Amazon's EC2 so you could use EC2 instances on B2 data without incurring a download charge (or not exposing that charge to our customers). But I don't know if Amazon is open to that kind of thing.

Re: Backblaze B2 Cloud Storage

#176
post #158
post #144

Earlier quoted context omitted.

Are you saying those reasons are not valid? And why is "trust" in quotes?

No! The reasons are absolutely valid. It's just interesting to see that the lean and cool startup is very similar to an established enterprise in that regard. The trust is in quotes because I'm not sure what to think about it. Every month I see a post here about some AWS service outage but it looks like nobody is getting nervous because of this. People just wait until it is fixed. On the other hand, I have experience…

most outages only happens on a single az. which is not really hard to handle. in over 1 year we had one outage on frankfurt. and that was just a small problem which a small reboot of our machines fixed the issues. oh and that happend automatically. the problem is you need to know that failures could happen. not only in the cloud but in the cloud these failures are more easily to handle since you could just create new boxes or use multi cloud envs.

Re: Backblaze B2 Cloud Storage

#177
post #169

Earlier quoted context omitted.

> as anyone who's used their software can tell you, it's throttled Brian from Backblaze here: no it is not throttled (by us). If you only have a 10 Mbit/sec upload capacity you are throttled by your ISP. Also make sure you visit our "Performance" tab in the online backup client and tweak a few settings, like increase the number of threads.

When I was a customer of BB I noticed no issue with the uploads, but actually when I had a flood and my hardware was destroyed, redownloading all my information was order of magnitudes slower. I tried from multiple physical locations but I could not increase my downloads past 1-2mbps, and for TB of data, that seemed like it was throttled by BB considering I was easily uploading 20mbps. I contacted BB support and they…

Brian from Backblaze here. I wonder if that was during the incredibly annoying "Comcast goes to war with Netflix" era that Backblaze got caught up in. That was Nov 2013 through Feb 2014, you can read a little about it here: https://www.backblaze.com/blog/obama-backs-net-neutrality/ (scroll down for our graphs showing our customers getting throttled). That seriously sucked for Backblaze.

But either way, we added threading to the bzdownloader (our custom application to download large restores) and if you tried it today crank it up to 10 threads and I swear you'll be happy with the download performance.

Re: Backblaze B2 Cloud Storage

#178
post #158
post #144

Earlier quoted context omitted.

Are you saying those reasons are not valid? And why is "trust" in quotes?

No! The reasons are absolutely valid. It's just interesting to see that the lean and cool startup is very similar to an established enterprise in that regard. The trust is in quotes because I'm not sure what to think about it. Every month I see a post here about some AWS service outage but it looks like nobody is getting nervous because of this. People just wait until it is fixed. On the other hand, I have experience…

Fair enough.

The reason you hear about so many AWS outages is because it's a massive service with so many users. If you build appropriately, you can have extremely good uptime built on AWS. They've earned tons of trust from their users.

Re: Backblaze B2 Cloud Storage

#180
post #128

Earlier quoted context omitted.

Sure, but it's not exactly putting them in a good light is it? Dressing up obsolete stuff as state of the art "same as your bank uses", while either being unwilling or unable to migrate to something more era-appropriate. Calls into question their competence, their honesty and their architecture all at once.

Wait, what about Blowfish is insecure? BCrypt is built on top of Blowfish. Blowfish supports key-lengths up to 448-bits. And I've never heard of a single criticism of the function. Its just kinda... less used than Rijndael because it didn't "officially" win the contest. But otherwise, it is a fine function. EDIT: Confused Twofish with Blowfish in the AES finalists.

Obsolete is not the same as insecure. But it is old, it does have its weaknesses, and there have been better options out there for a very long time. Why continue to use it? Is upgrading your crypto that difficult that you'd rather just leave it for another decade or two?

It also calls into question the nature of all the other crypto they're using - is that all >20 years old too? Still tuned for a world of 486's and 68040's?

Post reply on HN