1 00:00:00,115 --> 00:00:03,595 Today, we're talking about protecting cloud infrastructure. 2 00:00:03,835 --> 00:00:07,075 Like infrastructure as a service pass and SAS. 3 00:00:07,465 --> 00:00:12,385 We hope you make sense of the differences between these very similar acronyms and 4 00:00:12,385 --> 00:00:14,755 what parts of each need to be backed up. 5 00:00:15,415 --> 00:00:19,225 If you've ever wondered if your pass or SAS product needs to be backed 6 00:00:19,225 --> 00:00:21,445 up, you've come to the right place. 7 00:00:21,925 --> 00:00:25,195 Hi, I'm w Curtis Freston and they've been calling me Mr. 8 00:00:25,195 --> 00:00:29,155 Backup, since I wrote the first book on the topic over 20 years ago. 9 00:00:29,695 --> 00:00:33,295 I've dedicated over 30 years to making sure that people like you 10 00:00:33,535 --> 00:00:37,765 keep your data safe from accidents, disasters, and cyber attacks. 11 00:00:38,215 --> 00:00:43,075 My podcast turns on appreciated backup admins and to cyber recovery heroes. 12 00:00:43,345 --> 00:00:45,355 This is the backup wrap up. 13 00:01:06,799 --> 00:01:07,939 welcome to the show. 14 00:01:07,979 --> 00:01:11,525 I have with me the guy who makes me sweat. 15 00:01:12,055 --> 00:01:13,685 Prasanna Malaiyandi. 16 00:01:14,935 --> 00:01:15,505 How's it going? 17 00:01:15,505 --> 00:01:16,195 Prasanna? 18 00:01:17,345 --> 00:01:18,575 I'm good, Curtis. 19 00:01:18,575 --> 00:01:19,195 How are you doing? 20 00:01:19,195 --> 00:01:20,975 Are you get that? 21 00:01:20,985 --> 00:01:22,205 Sweating is good. 22 00:01:22,225 --> 00:01:24,335 They say it helps release toxins. 23 00:01:24,335 --> 00:01:26,015 it helps you lose weight. 24 00:01:26,405 --> 00:01:29,955 It helps you feel healthy and more alive and 25 00:01:30,000 --> 00:01:32,680 know if I felt alive after our walk this morning. 26 00:01:33,490 --> 00:01:37,330 yeah, for those who don't know, we live 400 miles apart, but we 27 00:01:37,330 --> 00:01:39,940 go on walks together, via this 28 00:01:39,945 --> 00:01:41,530 little device here in my air. 29 00:01:41,628 --> 00:01:42,318 Just like we do 30 00:01:42,323 --> 00:01:43,008 the podcast. 31 00:01:43,058 --> 00:01:44,438 We are not in the same room. 32 00:01:44,918 --> 00:01:46,948 We're not even in the same county. 33 00:01:47,768 --> 00:01:48,558 Walking is good. 34 00:01:48,588 --> 00:01:54,628 And I think the reason that you built up such a sweat today was I was a little, 35 00:01:54,678 --> 00:01:56,948 just a tiny bit delayed in joining 36 00:01:57,088 --> 00:01:58,688 15 minutes delayed, sir? 37 00:01:58,918 --> 00:01:59,378 Sir? 38 00:01:59,573 --> 00:02:02,353 I think it was actually like, yeah, it was, it was 15 minutes 39 00:02:02,373 --> 00:02:03,453 plus you started 10 minutes 40 00:02:03,453 --> 00:02:03,823 early. 41 00:02:04,143 --> 00:02:07,773 And I think you mentioned that you were going to wait till I called you 42 00:02:07,803 --> 00:02:09,593 to turn around and start walking back. 43 00:02:09,603 --> 00:02:10,533 So yeah, so that 44 00:02:10,593 --> 00:02:10,913 added 45 00:02:10,913 --> 00:02:11,063 up. 46 00:02:11,708 --> 00:02:15,238 Yeah, I walked one direction and I wasn't gonna turn around until you called me. 47 00:02:16,238 --> 00:02:19,658 So I did, but I did a good walk, did a good walk today. 48 00:02:20,448 --> 00:02:24,518 so let's stop talking about sweat and start talking about industry news. 49 00:02:24,938 --> 00:02:32,408 We have, I think a very apropos story that comes to us from Denmark, the, 50 00:02:32,458 --> 00:02:38,738 Danish hosting company that lost all of its customers data, or at 51 00:02:38,738 --> 00:02:42,038 least the majority of its customer data after a ransomware attack. 52 00:02:42,048 --> 00:02:42,958 What do you think about that? 53 00:02:43,958 --> 00:02:48,468 It's sad when these things don't shock you anymore, you know, you've sort of been 54 00:02:49,208 --> 00:02:51,278 acclimated to it, which is sad, right? 55 00:02:51,278 --> 00:02:55,088 But I'm not surprised as we've seen, and we've had guests talk 56 00:02:55,098 --> 00:02:56,118 about this in the past, right? 57 00:02:56,198 --> 00:02:58,398 Ransomware isn't dying down, right? 58 00:02:58,398 --> 00:02:59,668 It's just getting worse and worse. 59 00:02:59,668 --> 00:03:05,928 And people are going after these larger targets, if you will, right? 60 00:03:05,958 --> 00:03:07,518 More Centralized, right? 61 00:03:07,518 --> 00:03:10,138 Rather than necessarily going after like mom and pops and all the rest. 62 00:03:10,138 --> 00:03:13,738 And a service provider is like the perfect place to go attack, right? 63 00:03:13,738 --> 00:03:17,148 Because you have all these customers, data, all in a central place, right? 64 00:03:17,548 --> 00:03:20,088 They're offering services, it's probably business critical 65 00:03:20,098 --> 00:03:21,468 data, all the rest of that. 66 00:03:21,468 --> 00:03:23,078 And it's like, why not go after them? 67 00:03:23,088 --> 00:03:26,928 And that way you're negotiating with the service provider if you are trying 68 00:03:26,928 --> 00:03:28,588 to get ransom out of them, right? 69 00:03:28,588 --> 00:03:33,178 Getting them to pay versus dealing with every single end user out 70 00:03:33,223 --> 00:03:33,513 Yeah. 71 00:03:33,513 --> 00:03:38,363 The article mentioned that, this has been an, another new tactic by the ransomware 72 00:03:38,363 --> 00:03:42,823 folks, because by attacking a hosting provider, you create not one victim, 73 00:03:42,833 --> 00:03:47,423 but many victims, any one of which you could potentially go and, get them to, 74 00:03:47,423 --> 00:03:49,174 pay you a ransom in order to recover. 75 00:03:49,894 --> 00:03:52,964 Yeah, it reminds me a bit about the Rackspace attack 76 00:03:52,964 --> 00:03:54,584 that happened last year, right? 77 00:03:54,584 --> 00:03:58,404 Where they did target a very large service provider, right? 78 00:03:58,404 --> 00:03:59,984 Hitting their exchange environment, 79 00:04:00,394 --> 00:04:00,754 right? 80 00:04:01,034 --> 00:04:02,404 And it's the same sort of things. 81 00:04:02,404 --> 00:04:04,124 It feels a bit like Deja Vu, right? 82 00:04:04,464 --> 00:04:05,434 yeah, exactly. 83 00:04:05,694 --> 00:04:09,404 We encourage people that when they're hacked to tell people what happened. 84 00:04:09,924 --> 00:04:14,484 And there is a, what happened section in a page that is in Danish, 85 00:04:14,484 --> 00:04:19,224 but we have translated it via the, wonder of Google translator. 86 00:04:19,984 --> 00:04:26,884 And what happened was they were in the middle of a server move and they, there 87 00:04:26,884 --> 00:04:29,394 was a previously unknown infection. 88 00:04:29,434 --> 00:04:33,194 And during that server move, they were temporarily connected 89 00:04:33,214 --> 00:04:35,304 to, an administrative network. 90 00:04:35,444 --> 00:04:43,264 And that allowed the hackers to gain access and infect the, backup systems. 91 00:04:43,564 --> 00:04:45,534 And then via the backup systems. 92 00:04:45,834 --> 00:04:50,054 They were able to, this is one of the things we talked about many times 93 00:04:50,054 --> 00:04:54,024 that I know in recent episodes where we talked about that you really need 94 00:04:54,024 --> 00:04:57,034 to focus on the security of your backup and recovery system because. 95 00:04:57,369 --> 00:05:01,199 it is the goose that has the golden egg, right? 96 00:05:01,239 --> 00:05:02,159 It has everything. 97 00:05:02,275 --> 00:05:04,595 Or Crown Jewels, whichever way you want to think about it 98 00:05:04,635 --> 00:05:04,935 Yeah. 99 00:05:04,935 --> 00:05:05,785 The crown jewels. 100 00:05:05,785 --> 00:05:06,205 Yeah. 101 00:05:06,265 --> 00:05:07,785 basically it's one place. 102 00:05:07,785 --> 00:05:11,775 It's like they got the golden egg within the golden egg, right? 103 00:05:11,775 --> 00:05:15,995 They had the, this is the backups within the hosting provider that creates 104 00:05:16,005 --> 00:05:19,685 multiple, victims, but basically. 105 00:05:20,685 --> 00:05:24,815 I, I will say this, I have to admire the company because they're saying 106 00:05:24,815 --> 00:05:30,485 they are refusing to pay the ransom, even though this quite possibly will 107 00:05:30,485 --> 00:05:33,455 have significant, negative damage to the company because they don't 108 00:05:33,495 --> 00:05:35,395 have any backups of anybody's data. 109 00:05:36,030 --> 00:05:41,530 the craziest part was where they were suggestions for you to re, to 110 00:05:41,530 --> 00:05:46,270 rebuild your own website that actually pointed people at, the web archive, 111 00:05:47,270 --> 00:05:49,600 which is just the way back machine. 112 00:05:49,600 --> 00:05:49,980 Yeah. 113 00:05:50,250 --> 00:05:51,670 that's just fundamentally wrong. 114 00:05:52,220 --> 00:05:54,830 So just two things to also add to this new story quickly. 115 00:05:54,870 --> 00:05:58,530 I think one is the article I think that you had referred to earlier 116 00:05:58,530 --> 00:06:00,360 was found on Bleeping Computer. 117 00:06:00,925 --> 00:06:03,775 So if listeners, you want to go read more about it, go there. 118 00:06:03,775 --> 00:06:07,795 I think the other thing is it is mentioned that there are two companies that got 119 00:06:07,795 --> 00:06:10,765 hit, but the two companies actually belong to the same parent company. 120 00:06:10,765 --> 00:06:13,295 So there is that aspect as well. 121 00:06:13,315 --> 00:06:16,405 So if you do read that, Hey, there were two Nordic companies that got hit. 122 00:06:16,415 --> 00:06:17,795 They are Owned by the same company. 123 00:06:18,000 --> 00:06:18,540 Gotcha. 124 00:06:19,210 --> 00:06:24,820 and the good news category, we have the fact that Windows 10 is now going 125 00:06:24,820 --> 00:06:29,200 to have a built in backup, the built in backup features it looks like 126 00:06:29,200 --> 00:06:31,020 that were already in Windows 11. 127 00:06:31,220 --> 00:06:36,730 Microsoft was using that as a, has anyone in the history of computing 128 00:06:36,730 --> 00:06:40,490 migrated to a new operating system because it had better backup software? 129 00:06:41,540 --> 00:06:44,440 Of course, Curtis, that's the first reason to migrate. 130 00:06:44,550 --> 00:06:47,650 but that's what Microsoft was thinking, that people would upgrade 131 00:06:47,650 --> 00:06:52,640 to Windows 11 because it had better backup, and it's just not happening. 132 00:06:52,640 --> 00:06:56,950 People are still hovering on Windows 10, and so they decided to add 133 00:06:57,010 --> 00:07:00,567 these and they're saying that most of the functionality was not new. 134 00:07:01,147 --> 00:07:04,847 It was just all put under a single umbrellas to increase ease of use. 135 00:07:04,847 --> 00:07:06,697 And then there was some new functionality. 136 00:07:07,067 --> 00:07:07,727 So that's, 137 00:07:07,817 --> 00:07:12,307 don't know if you've ever tried to use backup in Windows 10, but it is awful. 138 00:07:12,377 --> 00:07:14,767 is this, what is this windows thing that you speak of? 139 00:07:15,887 --> 00:07:20,037 I'm sure you, so I have one Windows, no, actually I have two Windows boxes at home, 140 00:07:20,037 --> 00:07:22,767 but yes, for both, which I rarely use. 141 00:07:22,767 --> 00:07:25,697 And most of the time it is powered off just because of. 142 00:07:26,242 --> 00:07:27,672 Ransomware and other things like that. 143 00:07:27,672 --> 00:07:32,652 But yeah, so yeah, anytime I try to get in and figure things out, I'm like, oh 144 00:07:32,652 --> 00:07:34,592 my God, I just want to shoot myself. 145 00:07:34,622 --> 00:07:35,752 Just make it simple. 146 00:07:35,937 --> 00:07:37,197 Yeah, absolutely. 147 00:07:37,537 --> 00:07:41,127 I think this sort of the earlier story gives us a perfect segue 148 00:07:41,127 --> 00:07:42,707 into what we wanted to talk about. 149 00:07:43,122 --> 00:07:47,722 This is another part of our Backup to Basics series, where we review, 150 00:07:47,912 --> 00:07:52,612 basically stuff from the book, Modern Data Protection by the book, 151 00:07:52,632 --> 00:07:54,762 I mean, my book, from O'Reilly. 152 00:07:55,222 --> 00:07:59,992 And, we're looking at chapter eight, so first we've covered sort of traditional 153 00:07:59,992 --> 00:08:05,172 data sources, sort of servers and VMs and databases and things like that. 154 00:08:05,172 --> 00:08:09,562 Now we're starting to look at data sources that are relatively 155 00:08:09,562 --> 00:08:12,292 new, comparatively speaking. 156 00:08:12,792 --> 00:08:16,282 And, so the first thing we're going to talk about is the public cloud. 157 00:08:17,512 --> 00:08:18,342 is that a thing? 158 00:08:18,462 --> 00:08:19,872 What is a public cloud? 159 00:08:19,872 --> 00:08:21,312 Yeah, what is a public cloud? 160 00:08:21,312 --> 00:08:25,512 Because, honestly, if you take 10 people on the street, right, IT professionals, 161 00:08:25,732 --> 00:08:27,662 they don't have to be on the street because they don't have jobs, but 162 00:08:27,662 --> 00:08:29,182 just you find them somehow, right? 163 00:08:29,602 --> 00:08:32,752 and you talk to them, and you'll ask them, what's a public cloud? 164 00:08:32,752 --> 00:08:35,212 I bet you, you will get a half a dozen answers. 165 00:08:35,452 --> 00:08:36,422 Yeah, I think so. 166 00:08:36,512 --> 00:08:37,372 I still. 167 00:08:38,197 --> 00:08:41,627 Remember the first time I asked someone else, it happened to be Steven Foskett, 168 00:08:41,627 --> 00:08:46,117 I asked him what the, I remember we were having lunch in Manhattan, I still 169 00:08:46,117 --> 00:08:48,977 remember this, the first time I asked that question, what in the world is 170 00:08:48,977 --> 00:08:50,687 this cloud thing they're talking about? 171 00:08:51,747 --> 00:08:56,777 And, there is no such thing as a cloud, just somebody else's computer, right? 172 00:08:56,827 --> 00:08:59,667 that's basically what I always tell people. 173 00:08:59,967 --> 00:09:01,817 And the big thing, when... 174 00:09:02,817 --> 00:09:07,627 When we're talking, the big thing I want to make sure that people 175 00:09:07,627 --> 00:09:13,287 understand is this stuff still needs to be backed up, right? 176 00:09:13,947 --> 00:09:15,487 Everything needs to be backed up. 177 00:09:15,497 --> 00:09:16,567 The question is. 178 00:09:17,052 --> 00:09:18,682 Who is doing that backup? 179 00:09:19,542 --> 00:09:21,252 Cause the answer is not always the same. 180 00:09:22,102 --> 00:09:23,542 and, even if... 181 00:09:23,877 --> 00:09:27,857 You do figure out who is responsible and it's not you, you may still want 182 00:09:27,857 --> 00:09:31,427 to back it up in some fashion to avoid the new story we talked about 183 00:09:31,717 --> 00:09:32,497 Exactly. 184 00:09:32,567 --> 00:09:33,307 Exactly. 185 00:09:33,987 --> 00:09:38,707 So let's first talk, so let's look at the different parts of the public 186 00:09:38,707 --> 00:09:42,747 cloud and just talk about that. 187 00:09:42,767 --> 00:09:47,467 And the first is, the one that I hate the most to say as an acronym, cause 188 00:09:47,467 --> 00:09:50,187 it doesn't, you, I as that doesn't. 189 00:09:50,642 --> 00:09:53,222 Just doesn't, infrastructure as a service. 190 00:09:53,602 --> 00:09:56,742 what would you, how would you define that? 191 00:09:57,742 --> 00:10:02,382 In my mind, that literally is whatever you were running on your physical, 192 00:10:02,402 --> 00:10:07,082 like your applications were running somewhere on, in your own data centers. 193 00:10:07,692 --> 00:10:09,302 It needs to run somewhere in the cloud. 194 00:10:09,532 --> 00:10:13,792 All you're doing is you're hosting those applications on infrastructure 195 00:10:13,792 --> 00:10:17,602 that you are renting, borrowing, whatever you want to call it from 196 00:10:17,882 --> 00:10:19,202 the public cloud provider, right? 197 00:10:19,202 --> 00:10:24,682 So this is, if I look at AWS, these are like EC2 compute instances, right? 198 00:10:24,682 --> 00:10:29,027 So I am borrowing Infrastructure to host my application. 199 00:10:29,037 --> 00:10:33,657 It's probably EBS volumes because data needs to be stored on something 200 00:10:33,787 --> 00:10:34,097 Yeah. 201 00:10:34,117 --> 00:10:38,397 I would say I would include S3 and I would include the networking 202 00:10:38,397 --> 00:10:39,677 that's part of it as well. 203 00:10:39,727 --> 00:10:44,067 Basically storage, compute, and networking that you're renting. 204 00:10:44,767 --> 00:10:46,737 Is that, that seem about right? 205 00:10:47,737 --> 00:10:49,187 And so here's the question. 206 00:10:49,217 --> 00:10:49,527 What? 207 00:10:49,837 --> 00:10:50,497 Did you have something? 208 00:10:51,757 --> 00:10:54,827 which in the past was a great first step for a lot of people trying 209 00:10:54,827 --> 00:10:58,077 to figure out how do I go from my data center to the cloud, right? 210 00:10:58,077 --> 00:10:58,997 Because in. 211 00:10:59,377 --> 00:11:00,087 Your mind, right? 212 00:11:00,087 --> 00:11:01,507 It's just an easy lift and shift. 213 00:11:01,507 --> 00:11:05,217 Whatever I was running on premises, I just rent the infrastructure and 214 00:11:05,217 --> 00:11:06,877 then I just run my applications on it. 215 00:11:07,147 --> 00:11:08,897 It's not a real big, heavy lift for me. 216 00:11:08,897 --> 00:11:12,707 I'm not changing any applications or code or redoing things. 217 00:11:12,707 --> 00:11:15,177 It's just whatever was running here is now running there. 218 00:11:15,227 --> 00:11:15,707 Yeah. 219 00:11:15,757 --> 00:11:19,177 and just so that we're all on the same page, let's, because we use 220 00:11:19,177 --> 00:11:20,937 this term lift and shift quite a bit. 221 00:11:21,737 --> 00:11:23,027 and I often use it pejoratively. 222 00:11:24,457 --> 00:11:26,347 Can I put Lee at the end of pejorative? 223 00:11:26,467 --> 00:11:27,247 I think I can. 224 00:11:27,537 --> 00:11:29,317 I use it in the pejorative sense. 225 00:11:30,567 --> 00:11:32,867 And because I'm not a huge fan of lift and shift, right? 226 00:11:32,957 --> 00:11:35,677 it's a good like toe in the water. 227 00:11:36,537 --> 00:11:38,717 It allows you to start using the public cloud. 228 00:11:38,767 --> 00:11:41,207 It is a lousy way to use the public cloud. 229 00:11:41,207 --> 00:11:45,407 If all you do is take your VMs on prem and move it to VMs in the cloud. 230 00:11:45,417 --> 00:11:46,477 Why do I say that? 231 00:11:46,787 --> 00:11:51,447 Because you get some of the benefits and all of the badness, right? 232 00:11:51,447 --> 00:11:55,247 That basically you get, you basically, it's a really expensive 233 00:11:55,247 --> 00:11:57,687 way to have a data center, right? 234 00:11:58,007 --> 00:12:02,067 and so there's all these people that did this big lift and shift and 235 00:12:02,067 --> 00:12:04,747 they moved everything into cloud and they stopped using VMware and now 236 00:12:04,747 --> 00:12:09,467 they're using EC2 and then they're like, holy crap, this is expensive. 237 00:12:10,497 --> 00:12:14,337 You're like, You went from owning a car to renting a car and you're 238 00:12:14,337 --> 00:12:18,137 still driving it 24, seven, it's going to be expensive to do that way. 239 00:12:18,457 --> 00:12:23,427 The alternative is to do what's called refactor, which is, actually 240 00:12:24,127 --> 00:12:26,167 programming to the hundreds. 241 00:12:26,572 --> 00:12:30,582 Of services that Amazon runs and not just Amazon, but other providers, 242 00:12:31,072 --> 00:12:36,202 other services that they run, things that are, you use on demand and you 243 00:12:36,202 --> 00:12:41,552 pay for them as you use them rather than a server VM that's running 24 244 00:12:41,562 --> 00:12:42,982 seven, regardless of what it's doing. 245 00:12:43,222 --> 00:12:45,532 Anyway, I stepped down off my soapbox. 246 00:12:45,722 --> 00:12:49,352 I like what you talked about people being surprised by the cost aspect. 247 00:12:49,372 --> 00:12:52,032 And one of the things I just wanted to plug is, if you follow 248 00:12:52,032 --> 00:12:56,727 Corey Quinn on Twitter, I think he's part of Duck Bill Group. 249 00:12:56,777 --> 00:13:00,367 He does an amazing job of breaking down public cloud costs and why 250 00:13:00,367 --> 00:13:04,087 you should be careful when you are doing lift and shift to the 251 00:13:04,257 --> 00:13:04,887 Exactly. 252 00:13:04,977 --> 00:13:05,577 Exactly. 253 00:13:05,887 --> 00:13:06,837 It's a good resource. 254 00:13:07,317 --> 00:13:08,537 does this need to be backed up, 255 00:13:09,537 --> 00:13:10,347 Of course. 256 00:13:11,017 --> 00:13:11,517 is The data 257 00:13:11,517 --> 00:13:12,377 important to you? 258 00:13:12,467 --> 00:13:12,937 yes. 259 00:13:13,787 --> 00:13:14,717 I'll give you a clue. 260 00:13:14,937 --> 00:13:16,267 The answer is always yes. 261 00:13:16,577 --> 00:13:18,077 So here's a question. 262 00:13:18,637 --> 00:13:22,487 Let's talk specifically AWS, because you and I have spent a lot of time in AWS. 263 00:13:23,027 --> 00:13:24,807 it's not the only cloud provider, it's just the one I 264 00:13:24,817 --> 00:13:26,007 have the most experience with. 265 00:13:26,507 --> 00:13:34,517 If you have EC2 instances, Are they backed up in any way if you don't do anything? 266 00:13:35,517 --> 00:13:36,117 I do not 267 00:13:36,237 --> 00:13:37,177 I don't think so. 268 00:13:37,297 --> 00:13:40,487 and when you talk about EC2, remember EC2 is just compute. 269 00:13:40,497 --> 00:13:42,897 You need to actually attach a volume, which is an EBS 270 00:13:42,897 --> 00:13:44,387 volume, in order to actually 271 00:13:44,607 --> 00:13:44,977 right. 272 00:13:45,007 --> 00:13:45,507 Really what 273 00:13:45,587 --> 00:13:45,877 Right? 274 00:13:45,877 --> 00:13:46,197 And I 275 00:13:46,237 --> 00:13:48,587 the EBS volume that's behind that. 276 00:13:48,937 --> 00:13:56,027 And yeah, it is my understanding that with EC2, If you have a VM, literally nothing 277 00:13:56,027 --> 00:14:00,277 that anyone would literally nothing like it's not even, there's not even something 278 00:14:00,287 --> 00:14:04,797 that maybe someone consider a backup, but others would not, there's nothing right. 279 00:14:04,807 --> 00:14:07,597 You are 100 percent responsible for that. 280 00:14:08,097 --> 00:14:08,597 Exactly. 281 00:14:08,597 --> 00:14:08,757 Yeah. 282 00:14:08,817 --> 00:14:12,387 Unless you do take advantage of things like EBS snapshots. 283 00:14:12,752 --> 00:14:13,132 to you. 284 00:14:13,282 --> 00:14:14,372 The tools are there. 285 00:14:14,442 --> 00:14:18,912 But my point of making is specifically with, again, this is just speaking of EC2. 286 00:14:19,212 --> 00:14:21,202 I think it's actually the same and other. 287 00:14:21,872 --> 00:14:26,022 like Azure and GCP, that specifically VMs, they're assuming, you're running 288 00:14:26,022 --> 00:14:28,452 this thing, you're in charge, right? 289 00:14:28,952 --> 00:14:32,512 there are two ways to back up a VM in the cloud, right? 290 00:14:32,542 --> 00:14:35,232 You can use the built in tools. 291 00:14:35,752 --> 00:14:37,462 essentially, they call them snapshots. 292 00:14:37,512 --> 00:14:38,962 I don't like to call them snapshots. 293 00:14:38,992 --> 00:14:40,822 They are actually image copies. 294 00:14:41,272 --> 00:14:45,392 It's actually a copy of that drive made to another location. 295 00:14:45,392 --> 00:14:48,882 In the case of AWS, it is, it's in S3, right? 296 00:14:48,902 --> 00:14:50,982 EBS snapshots are stored in S3. 297 00:14:50,982 --> 00:14:55,092 So they're stored as an object and you can do incremental snapshots, right? 298 00:14:55,692 --> 00:14:57,952 then what do you do once you've done that? 299 00:14:58,452 --> 00:15:02,072 So since the EBS snapshot lands in S3, right, you get all the benefits 300 00:15:02,072 --> 00:15:07,062 of S3, right, so it is replicated within three availability zones, 301 00:15:07,062 --> 00:15:10,202 right, the only downside is, Right? 302 00:15:10,202 --> 00:15:11,092 That's just one copy. 303 00:15:11,092 --> 00:15:13,042 You still want to follow the 3 2 1 rule, right? 304 00:15:13,042 --> 00:15:16,482 So you want to make sure that that one copy also makes it into a 305 00:15:16,522 --> 00:15:18,162 different region, a different account. 306 00:15:18,162 --> 00:15:21,652 So using S3 technologies, you can make sure the image copy that's in 307 00:15:21,682 --> 00:15:25,502 S3 in a local spot gets replicated to somewhere else in a different account. 308 00:15:25,512 --> 00:15:26,732 So you get protected as well. 309 00:15:26,832 --> 00:15:27,452 exactly. 310 00:15:27,672 --> 00:15:29,342 Codespace, Codespaces. 311 00:15:29,522 --> 00:15:30,982 That's all I'm going to say, right? 312 00:15:31,012 --> 00:15:31,852 Codespaces. 313 00:15:31,852 --> 00:15:33,082 com, read that story. 314 00:15:33,352 --> 00:15:34,222 That's why. 315 00:15:34,577 --> 00:15:37,627 You've got to put it in a different account and a different region, right? 316 00:15:37,637 --> 00:15:41,277 That, that, that's the way in the cloud. 317 00:15:41,287 --> 00:15:44,367 That's the way you comply with the 3 2 1 rule, right? 318 00:15:45,637 --> 00:15:48,997 Veeam likes to turn it into 0. 319 00:15:49,307 --> 00:15:50,487 I don't like to do that. 320 00:15:50,487 --> 00:15:54,797 I just like to say, listen, just properly follow by the 3 2 1 rule that says 321 00:15:55,117 --> 00:16:00,227 having multiple things on different, the idea of the two is having it on two 322 00:16:00,227 --> 00:16:01,567 different things that have different. 323 00:16:02,567 --> 00:16:04,117 Risk profiles, right? 324 00:16:04,127 --> 00:16:05,787 So put it in a different region. 325 00:16:06,117 --> 00:16:09,717 And also the one, I think the truly one is to have it offsite, not 326 00:16:09,717 --> 00:16:12,487 only to have it in another region, but to have it in another account. 327 00:16:12,527 --> 00:16:15,517 So if you're one main account of Compromised, then it's not going 328 00:16:15,517 --> 00:16:16,677 to, it's not going to be over there. 329 00:16:17,637 --> 00:16:21,497 And maybe for listeners who may not have heard us talk about 3 2 1 rule 330 00:16:21,497 --> 00:16:22,737 before, do you want to explain what the 331 00:16:22,737 --> 00:16:23,577 3 2 1 rule is? 332 00:16:24,087 --> 00:16:24,427 yeah. 333 00:16:24,427 --> 00:16:25,752 if, yeah, thanks. 334 00:16:25,752 --> 00:16:32,237 So 3 2 1 rule is just a rule of thumb that was coined by somebody who we 335 00:16:32,237 --> 00:16:34,087 actually had on the podcast, Peter Krogh. 336 00:16:34,512 --> 00:16:37,302 he's a digital photographer and he just said, you want to have three 337 00:16:37,302 --> 00:16:38,672 copies of every piece of data. 338 00:16:38,932 --> 00:16:42,272 He does see the first, the original is one of those copies. 339 00:16:42,582 --> 00:16:46,512 So then the two of those three, two of those, you want them to have 340 00:16:46,512 --> 00:16:49,052 them on two different risk profiles. 341 00:16:49,112 --> 00:16:51,922 He's talking about maybe two different kinds of media. 342 00:16:52,212 --> 00:16:55,432 and in this case, we're saying put it in two different regions. 343 00:16:55,722 --> 00:16:59,042 some people like to take that to the point of saying, we're going 344 00:16:59,042 --> 00:17:00,702 to put one on disc and one on tape. 345 00:17:00,952 --> 00:17:02,872 I don't have any disagreement with that. 346 00:17:03,312 --> 00:17:07,412 and then the one is, making sure that one of the copies is offsite. 347 00:17:07,462 --> 00:17:09,652 In the cloud, there is no such thing as offsite. 348 00:17:09,982 --> 00:17:12,212 So that's again, why we talk about a different region. 349 00:17:12,212 --> 00:17:13,912 And I think the different account is. 350 00:17:15,157 --> 00:17:15,887 gets added to 351 00:17:16,087 --> 00:17:20,807 mainly today we use the 3 2 1 to show things that aren't backups, right? 352 00:17:21,207 --> 00:17:25,187 We're gonna get to that in a minute Things that definitely are not backups. 353 00:17:25,717 --> 00:17:26,807 Alright, so what's next? 354 00:17:26,817 --> 00:17:27,677 We're talking about PaaS. 355 00:17:27,677 --> 00:17:29,147 What is PaaS Prasanna? 356 00:17:30,147 --> 00:17:32,777 platform as a service, right? 357 00:17:32,777 --> 00:17:37,797 And I think this evolved because, okay, IaaS was the first level, 358 00:17:37,797 --> 00:17:38,827 the base level, if you will. 359 00:17:38,827 --> 00:17:41,117 And then people were like, that's too complicated, right? 360 00:17:41,117 --> 00:17:46,187 It basically doesn't help simplify my management aspects, right? 361 00:17:46,187 --> 00:17:48,087 I'm still managing infrastructure. 362 00:17:48,087 --> 00:17:49,687 I don't want to have to deal with that. 363 00:17:49,687 --> 00:17:53,347 And so PaaS was built on top and it's more platform as a service. 364 00:17:53,347 --> 00:17:55,147 So these are things like. 365 00:17:55,767 --> 00:17:58,497 You'll still be managing and deploying your applications, but you don't 366 00:17:58,497 --> 00:18:01,627 have to deal with all the underlying infrastructure and figuring out 367 00:18:01,627 --> 00:18:04,437 how many EC2 instances you have to spin up and everything else. 368 00:18:04,837 --> 00:18:09,717 So an example of this would be AWS RDS, which is their database 369 00:18:09,717 --> 00:18:12,837 service, which allows you to say. 370 00:18:13,252 --> 00:18:16,332 Provision for MySQL or Oracle, right? 371 00:18:16,382 --> 00:18:17,602 or Postgres, I believe. 372 00:18:17,872 --> 00:18:22,302 And so you can spin up these database instances without having to worry about, 373 00:18:22,302 --> 00:18:25,782 okay, how many individual EC2 nodes do I need and all the rest of that. 374 00:18:25,837 --> 00:18:30,087 Yeah, instead of saying, build a box and then install Oracle on it, right? 375 00:18:30,107 --> 00:18:32,697 They're like, here's an Oracle database, right? 376 00:18:32,997 --> 00:18:37,407 Here's your, here's your admin password and log in and do all the things, 377 00:18:37,457 --> 00:18:40,867 Tell us how big you want it, what tables you want, all those things. 378 00:18:40,867 --> 00:18:44,117 And you're administering it, maybe even not even through the 379 00:18:44,117 --> 00:18:45,387 traditional Oracle interface. 380 00:18:45,457 --> 00:18:49,957 You may have a, Another UI that you're using to create the tables. 381 00:18:50,007 --> 00:18:54,777 you probably in the case of Oracle and MySQL, you probably can also 382 00:18:54,777 --> 00:18:56,797 administer it via the standard tools. 383 00:18:57,092 --> 00:19:01,212 But you may have this additional UI and you just get this, here's this database. 384 00:19:01,572 --> 00:19:04,892 Now, I won't bother asking, should it be backed up? 385 00:19:05,352 --> 00:19:06,632 But here's my question. 386 00:19:07,232 --> 00:19:13,302 Do you know whether or not RDS databases, for example, are automatically backed up? 387 00:19:14,302 --> 00:19:20,402 So I think that they do have a policy that you can create to say, 388 00:19:20,432 --> 00:19:22,552 I want to do automatic backups. 389 00:19:22,902 --> 00:19:25,372 I am not sure if it's default on or not. 390 00:19:25,447 --> 00:19:29,387 I believe that it actually is by default on. 391 00:19:29,817 --> 00:19:34,107 but it's just a very basic, like snapshot replicated S3. 392 00:19:34,492 --> 00:19:37,012 Stays in the same account, stays in the same region, all of that. 393 00:19:37,292 --> 00:19:37,922 I'm pretty 394 00:19:38,067 --> 00:19:39,137 For 30 days only, 395 00:19:39,572 --> 00:19:40,612 for 30 days, yeah. 396 00:19:40,952 --> 00:19:43,032 and then if you want to do more than that, if you want to replicate 397 00:19:43,032 --> 00:19:46,082 to another region, if you want to replicate to another account, which you 398 00:19:46,092 --> 00:19:48,932 should, that's where it's up to you. 399 00:19:49,442 --> 00:19:56,112 but even that, again, that's still, if you're not getting it out of that account. 400 00:19:56,807 --> 00:19:59,097 I don't think of that as a valid backup. 401 00:19:59,337 --> 00:20:04,977 Leave it in the account, yes, for convenience and ease of restore, but get 402 00:20:04,977 --> 00:20:09,304 it out of the account from a security perspective and a risk perspective, 403 00:20:09,412 --> 00:20:11,922 and that other account should be locked down, right? 404 00:20:11,942 --> 00:20:14,922 You don't want anyone and everyone to have access. 405 00:20:15,162 --> 00:20:17,302 if someone gets access to the production account, you don't want 406 00:20:17,302 --> 00:20:19,642 them to necessarily be able to quickly get access to that backup 407 00:20:19,867 --> 00:20:20,597 exactly. 408 00:20:20,747 --> 00:20:25,027 in addition to locking it down and having super crazy MFA and all of those 409 00:20:25,027 --> 00:20:29,667 things, I would configure it so that if, and when somebody does log into 410 00:20:29,667 --> 00:20:31,677 it, it sets off all kinds of alarms. 411 00:20:32,082 --> 00:20:33,802 that go to important 412 00:20:33,852 --> 00:20:34,712 Will Robinson, 413 00:20:34,942 --> 00:20:35,582 Will Robinson, 414 00:20:35,582 --> 00:20:35,932 Yeah. 415 00:20:36,342 --> 00:20:38,652 some of our listeners might not get that reference, but... 416 00:20:39,875 --> 00:20:41,745 Um, so yeah. 417 00:20:42,775 --> 00:20:45,765 Also needs to be backed up, also needs to be transferred. 418 00:20:46,345 --> 00:20:47,925 with the case of EC2, right? 419 00:20:47,925 --> 00:20:50,605 There's a couple different ways we talked about that, the snapshot 420 00:20:50,605 --> 00:20:52,495 plus replication is the typical way. 421 00:20:52,885 --> 00:20:56,255 There, you can also load an agent on an EC2, thing. 422 00:20:56,795 --> 00:21:01,325 With RDS specifically, and again, we're only talking about RDS 423 00:21:01,325 --> 00:21:03,695 just because this is where you and I have a lot of experience. 424 00:21:03,695 --> 00:21:06,775 There are other tools you need to look into those tools. 425 00:21:08,125 --> 00:21:16,015 In the case of RDS, I'm pretty sure you're stuck with the RDS way of backing up. 426 00:21:16,665 --> 00:21:18,475 You can't put in an agent. 427 00:21:19,055 --> 00:21:23,295 And I know, for example, in the case of Oracle, and I don't know 428 00:21:23,295 --> 00:21:26,905 if they've changed this, but the last time I checked, RMAN backups 429 00:21:26,955 --> 00:21:30,405 work, RMAN restores do not, which 430 00:21:31,605 --> 00:21:32,355 Yep, which is 431 00:21:32,625 --> 00:21:37,035 is really weird, and just wrong, right? 432 00:21:38,520 --> 00:21:40,880 I don't even know how, like, how you would go about restoring. 433 00:21:41,080 --> 00:21:46,000 so what do you think people that are doing, RDS backups, via non 434 00:21:46,000 --> 00:21:48,530 standard, or standard ways, what do you think they should do to 435 00:21:48,530 --> 00:21:50,450 know exactly how that stuff works? 436 00:21:51,450 --> 00:21:53,580 they should try it out, right? 437 00:21:53,770 --> 00:21:57,090 Test your backups, do your test restores, right? 438 00:21:57,450 --> 00:22:00,890 Try these various scenarios and figure out, can I restore a tablespace? 439 00:22:00,930 --> 00:22:02,660 Can I restore an instance, right? 440 00:22:03,140 --> 00:22:04,790 Can I restore... 441 00:22:05,085 --> 00:22:05,985 Logs, right? 442 00:22:05,985 --> 00:22:06,805 Roll back in time. 443 00:22:06,905 --> 00:22:09,025 Yeah, roll back in time, right? 444 00:22:09,075 --> 00:22:10,385 Do all those things work? 445 00:22:10,435 --> 00:22:12,965 Because it's better to try it now before you actually need 446 00:22:12,965 --> 00:22:14,485 it, rather than scrambling 447 00:22:14,620 --> 00:22:15,340 Exactly. 448 00:22:15,670 --> 00:22:18,560 and there are all kinds of different PaaS. 449 00:22:18,580 --> 00:22:22,820 Generally, when I think about PaaS, generally, I find myself talking 450 00:22:22,820 --> 00:22:25,355 about a database of some sort. 451 00:22:25,865 --> 00:22:28,875 I was also thinking about things like VMware right? 452 00:22:28,875 --> 00:22:30,415 Which runs in the public cloud, right? 453 00:22:30,435 --> 00:22:32,105 That's probably more of a PaaS. 454 00:22:32,565 --> 00:22:33,675 no, I see that. 455 00:22:33,685 --> 00:22:34,795 I see that as IS. 456 00:22:34,795 --> 00:22:35,245 Yeah. 457 00:22:35,395 --> 00:22:35,595 Yeah. 458 00:22:35,645 --> 00:22:37,965 Because again, you're just managing VMs, right? 459 00:22:38,205 --> 00:22:39,195 now, let's talk about that. 460 00:22:39,205 --> 00:22:42,425 VMware Cloud on AWS is a great thing to talk about. 461 00:22:43,035 --> 00:22:48,290 And that is that It's, it has a completely different backup 462 00:22:48,290 --> 00:22:49,910 and recovery paradigm, right? 463 00:22:49,910 --> 00:22:55,040 You need to use a tool that knows how to backup VMware cloud, on a 464 00:22:55,045 --> 00:22:59,300 w s or on the other places where VMware cloud happens to run. 465 00:22:59,950 --> 00:23:03,950 And, any decent modern backup and recovery tool is going to have that. 466 00:23:04,950 --> 00:23:11,930 but don't assume if you're moving from VMware on prem to VMware cloud on AWS, 467 00:23:11,940 --> 00:23:13,570 don't assume that your backup product. 468 00:23:14,935 --> 00:23:19,215 we'll support it because one big thing, for example, is, like 469 00:23:19,465 --> 00:23:21,505 you, you have to use the APIs. 470 00:23:21,635 --> 00:23:26,225 You can't, there, there's no, place where you can, install stuff to, 471 00:23:26,275 --> 00:23:27,825 to do things like the old way. 472 00:23:28,205 --> 00:23:30,215 you have to use the APIs. 473 00:23:31,015 --> 00:23:34,775 the other thing also, specifically with VMware Cloud, is you have to 474 00:23:34,775 --> 00:23:37,915 also check to see, because I know at least in the past, there was some 475 00:23:37,915 --> 00:23:42,925 functionality which isn't fully available in the VMware Cloud environment just 476 00:23:42,935 --> 00:23:46,905 because of the infrastructure and other complexities that you might 477 00:23:46,915 --> 00:23:48,675 have been able to do on premises. 478 00:23:48,685 --> 00:23:51,815 if you were relying on certain restore functionality specifically, 479 00:23:52,195 --> 00:23:53,685 that may not work in VMware Cloud. 480 00:23:53,890 --> 00:23:59,410 By the way, speaking of VMware cloud, six years ago today, according to 481 00:23:59,410 --> 00:24:04,420 photos in my library, VMware was talking about VMware cloud on AWS 482 00:24:04,960 --> 00:24:10,265 at VMworld that I was attending because it popped up a photo of the. 483 00:24:10,715 --> 00:24:13,535 Of the, the slides I was like, what? 484 00:24:13,905 --> 00:24:16,665 They're kind of run VMware on AWS. 485 00:24:16,705 --> 00:24:19,305 what in the world, who would want to do that? 486 00:24:19,345 --> 00:24:23,175 I said, and once again, the world said us. 487 00:24:24,175 --> 00:24:24,525 Yeah. 488 00:24:24,800 --> 00:24:25,210 All right. 489 00:24:25,315 --> 00:24:29,965 so the next is Server Serverless Services. 490 00:24:30,095 --> 00:24:31,175 that's a mouthful. 491 00:24:31,540 --> 00:24:32,760 That's a handful. 492 00:24:32,760 --> 00:24:35,370 Yeah, I was going to say, say that 10 times fast, Curtis. 493 00:24:35,400 --> 00:24:36,450 Yeah, I'm not gonna do that. 494 00:24:36,750 --> 00:24:39,280 So this is like Lambda and other things. 495 00:24:40,320 --> 00:24:42,960 remember there's always a server behind Serverless Services. 496 00:24:43,960 --> 00:24:52,900 But, I don't, these are typically actions that do things against 497 00:24:52,950 --> 00:24:57,300 other things that I don't think. 498 00:24:57,360 --> 00:24:59,950 is this the one exception to the backup rule? 499 00:25:01,215 --> 00:25:02,955 So I would disagree 500 00:25:03,040 --> 00:25:03,600 Okay. 501 00:25:03,680 --> 00:25:03,820 All 502 00:25:04,125 --> 00:25:07,595 I think you still need to back up because think of serverless 503 00:25:07,625 --> 00:25:09,265 as your writing function. 504 00:25:10,465 --> 00:25:11,795 I think you have to back up the actual 505 00:25:12,125 --> 00:25:16,255 Okay, so the function that you've created, yeah, just this is just 506 00:25:16,255 --> 00:25:17,595 like Kubernetes and Dockers. 507 00:25:17,815 --> 00:25:21,965 You're backing up sort of the configuration, but the thing the 508 00:25:21,965 --> 00:25:28,845 serverless action is doing is going to affect some other piece of storage. 509 00:25:28,845 --> 00:25:30,915 That's the thing that you're going to be backing up. 510 00:25:31,995 --> 00:25:33,725 Yeah, you should already be backing that up 511 00:25:33,905 --> 00:25:34,225 Okay. 512 00:25:34,805 --> 00:25:38,035 so I, as I was saying it, I was probably in back of my brain was 513 00:25:38,035 --> 00:25:39,415 like, what about the configuration? 514 00:25:39,455 --> 00:25:39,765 Yeah. 515 00:25:39,995 --> 00:25:42,195 So yes, you want to back up the configuration of the 516 00:25:42,205 --> 00:25:46,015 thing that you developed that you're running as a function. 517 00:25:46,115 --> 00:25:49,325 and it may be complicated because one of the things like I know We haven't 518 00:25:49,325 --> 00:25:53,305 quite talked about it on this episode, but it's why do you back up right? 519 00:25:53,345 --> 00:25:56,885 It's to be able to restore in the case of different types of failures, right? 520 00:25:56,905 --> 00:26:02,095 And one of it is hey that lambda file or the serverless function that I wrote. 521 00:26:02,545 --> 00:26:06,485 It's not behaving the way I want it I want to be able to go back in time and restore 522 00:26:06,485 --> 00:26:08,365 whatever it was from like a month ago 523 00:26:08,485 --> 00:26:08,955 Yeah. 524 00:26:09,075 --> 00:26:09,305 Yeah. 525 00:26:09,305 --> 00:26:10,825 The whole agile development model. 526 00:26:10,825 --> 00:26:14,855 I'm 17 revisions in and, yeah, exactly. 527 00:26:15,610 --> 00:26:20,730 that is one of the reasons we restore is developers mess up stuff, right? 528 00:26:21,190 --> 00:26:21,590 All right. 529 00:26:21,590 --> 00:26:26,570 So let's talk about our next cloud resource that we may or may not want 530 00:26:26,580 --> 00:26:29,270 to back up a little thing called SaaS. 531 00:26:29,850 --> 00:26:30,070 sa. 532 00:26:31,070 --> 00:26:31,590 Software 533 00:26:31,810 --> 00:26:36,510 so I think first before, so before we get into whether or not we should 534 00:26:36,510 --> 00:26:40,580 back it up, Curtis, I want you to give your definition of what you think S 535 00:26:40,950 --> 00:26:46,650 is and what you think ssas is not, because there's a lot of confusion out 536 00:26:46,650 --> 00:26:48,660 there when people use the word SaaS, 537 00:26:48,700 --> 00:26:49,090 Yeah, 538 00:26:49,530 --> 00:26:49,680 and 539 00:26:49,730 --> 00:26:52,960 there are two things that are often marketed as SaaS. 540 00:26:53,380 --> 00:26:55,960 and there's one really big company that's marketing. 541 00:26:56,455 --> 00:26:57,455 itself is SaaS. 542 00:26:57,455 --> 00:26:59,205 And I'm like, I'm sorry, that is not SaaS. 543 00:27:00,135 --> 00:27:03,495 SaaS is, it's easier to define it. 544 00:27:03,900 --> 00:27:08,100 in terms of to give examples of it, then, An example of SaaS is 545 00:27:08,100 --> 00:27:11,970 Microsoft 365, Salesforce, HubSpot. 546 00:27:12,450 --> 00:27:13,810 It's a service. 547 00:27:13,850 --> 00:27:15,000 It's an application. 548 00:27:15,000 --> 00:27:15,640 Yes. 549 00:27:15,850 --> 00:27:19,670 But it's an application where you don't manage any of the infrastructure. 550 00:27:20,210 --> 00:27:22,140 You just use the thing. 551 00:27:22,560 --> 00:27:27,520 You go to Microsoft 365 and you say, I want to add 7, 000 users and 552 00:27:27,530 --> 00:27:29,830 magic happens underneath the covers. 553 00:27:30,230 --> 00:27:33,090 All of the, all of the infrastructure that does have to 554 00:27:33,100 --> 00:27:34,800 be provisioned to make that happen. 555 00:27:35,110 --> 00:27:39,810 That happens without you, hopefully without you even feeling it. 556 00:27:39,920 --> 00:27:43,200 it may, if you go and you say, I need to provision a hundred thousand users. 557 00:27:43,530 --> 00:27:48,290 Microsoft 365 might say, give me a minute because it's got to go out 558 00:27:48,290 --> 00:27:49,500 and provision a bunch of storage. 559 00:27:50,060 --> 00:27:51,130 But, go ahead. 560 00:27:52,595 --> 00:27:55,295 or even like how we're recording this podcast. 561 00:27:56,600 --> 00:27:57,810 Oh, yeah, this is a SaaS. 562 00:27:57,830 --> 00:28:01,410 We're now using Squadcast, to record this podcast. 563 00:28:01,440 --> 00:28:06,440 And you and I log in, we go to a website, we go, we say record. 564 00:28:07,125 --> 00:28:09,635 It does the magic and then saves the data. 565 00:28:09,645 --> 00:28:12,305 That is another example of a SaaS service. 566 00:28:12,965 --> 00:28:15,675 What is not an example of a SaaS service? 567 00:28:16,095 --> 00:28:18,745 Adobe software. 568 00:28:18,845 --> 00:28:20,195 This is, 569 00:28:20,210 --> 00:28:21,070 Creative Cloud. 570 00:28:21,215 --> 00:28:24,495 yeah, Adobe Creative Cloud is not SaaS. 571 00:28:24,515 --> 00:28:27,775 They keep like the CEO of Adobe say, we want to be a hundred 572 00:28:27,775 --> 00:28:30,345 percent SaaS by 2025 or whatever. 573 00:28:30,345 --> 00:28:32,705 And I'm like, you're not 0 percent SaaS. 574 00:28:33,705 --> 00:28:38,465 What is often called SaaS is subscription based pricing. 575 00:28:39,145 --> 00:28:42,845 They're saying, you're, it's a software as a service, right? 576 00:28:43,395 --> 00:28:46,295 No, it's software as a subscription, right? 577 00:28:46,325 --> 00:28:48,015 Which also by the way is SaaS. 578 00:28:48,885 --> 00:28:49,895 It comes out as SaaS. 579 00:28:50,340 --> 00:28:53,460 so so I think there is one correction though. 580 00:28:53,460 --> 00:28:56,220 I know with Adobe, there is a lot of the tools. 581 00:28:56,280 --> 00:29:01,850 one reason why I know you complain about it is you want to use Photoshop, right? 582 00:29:01,850 --> 00:29:06,135 You subscribe to Creative Cloud, you download Photoshop, you have to 583 00:29:06,135 --> 00:29:09,535 install it, you have to manage the updates, you're doing all of that. 584 00:29:09,885 --> 00:29:14,675 I believe now Adobe is actually pushing towards a true SaaS product for 585 00:29:14,675 --> 00:29:18,205 Photoshop where it is everything done on 586 00:29:18,215 --> 00:29:21,685 When that happens, I will rescind my, thing. 587 00:29:21,895 --> 00:29:26,470 But if I'm downloading something And I'm installing it on my infrastructure. 588 00:29:26,480 --> 00:29:27,930 That is not SaaS. 589 00:29:28,310 --> 00:29:31,910 I can think of, I don't want to pick on them by name, but there's 590 00:29:31,910 --> 00:29:36,360 a backup vendor that sells their stuff now through subscription 591 00:29:36,360 --> 00:29:38,480 based pricing and they call it SaaS. 592 00:29:38,630 --> 00:29:40,420 And I'm like, I'm sorry, that is not SaaS. 593 00:29:40,980 --> 00:29:41,320 Right. 594 00:29:41,500 --> 00:29:43,580 and I don't really care what you call your product. 595 00:29:43,580 --> 00:29:44,030 It's just. 596 00:29:44,615 --> 00:29:49,565 It's just a little confusing when we're trying to talk about, backing up SaaS. 597 00:29:49,615 --> 00:29:52,455 I think that when you say SaaS, it should mean one thing. 598 00:29:52,735 --> 00:29:58,385 And it means like Microsoft 365, a service that I use via, I'll give you one. 599 00:29:58,445 --> 00:30:01,505 if I've got, I don't think anyone does this, but if I 600 00:30:01,505 --> 00:30:04,830 had To, what, you know what? 601 00:30:05,240 --> 00:30:05,790 Zoom. 602 00:30:05,970 --> 00:30:08,210 Zoom is a perfect example. 603 00:30:08,550 --> 00:30:12,800 I have to install a piece of software to use Zoom. 604 00:30:13,170 --> 00:30:18,740 But it's just a UI to the infrastructure that's running in the background, right? 605 00:30:18,740 --> 00:30:19,510 It's not... 606 00:30:19,930 --> 00:30:22,380 I'm not running Zoom on my platform. 607 00:30:22,690 --> 00:30:23,250 That's still 608 00:30:23,545 --> 00:30:29,005 and Yes, and technically, you could also not have to install a 609 00:30:29,405 --> 00:30:33,485 client locally, you could always use a web client and join via that. 610 00:30:34,540 --> 00:30:40,070 yeah, so here's my, we've talked about this plenty of times, but my biggest 611 00:30:40,070 --> 00:30:44,570 problem with SaaS is it's so many people seem to think that because 612 00:30:44,570 --> 00:30:49,300 I'm getting the entire application delivered to me on a silver platter. 613 00:30:49,745 --> 00:30:52,600 Backup is part of that service. 614 00:30:53,675 --> 00:30:54,665 Isn't it, Curtis? 615 00:30:54,685 --> 00:30:55,325 Come on! 616 00:30:56,395 --> 00:30:57,685 Now you're just poking the bear. 617 00:30:58,205 --> 00:31:00,405 yeah, it's not, here's the thing. 618 00:31:00,545 --> 00:31:03,475 There may be a SaaS service out there. 619 00:31:03,475 --> 00:31:07,365 In fact, I may have encountered one where they actually include backups 620 00:31:07,365 --> 00:31:09,565 as part of the infrastructure. 621 00:31:10,220 --> 00:31:15,290 And, it's in the service contract, it's in the documentation, right? 622 00:31:15,610 --> 00:31:21,200 and those backups, by the way, if you actually have backups as part of the 623 00:31:21,200 --> 00:31:25,030 product, all I want to know is how do they conform to the 3 2 1 rule? 624 00:31:25,040 --> 00:31:28,560 How can I make sure that at least one of those copies is being managed? 625 00:31:29,030 --> 00:31:32,710 In a different location and has a different risk profile 626 00:31:32,730 --> 00:31:34,830 than the primary stuff. 627 00:31:35,680 --> 00:31:40,600 My, can you remember what three letter acronym I would throw out to remind 628 00:31:40,600 --> 00:31:43,510 people about what happens when you have the backups managed by the same people? 629 00:31:44,720 --> 00:31:44,950 OVH. 630 00:31:45,550 --> 00:31:46,300 Exactly. 631 00:31:47,680 --> 00:31:48,150 Yeah. 632 00:31:48,530 --> 00:31:53,160 OVH, the largest cloud provider headquartered in France, had a backup 633 00:31:53,160 --> 00:31:57,210 service for the back, the servers that they were backing up, and the data was 634 00:31:57,210 --> 00:31:59,600 stored literally in the same data center. 635 00:32:00,550 --> 00:32:04,560 And when they had this giant fire, it took out both the 636 00:32:04,560 --> 00:32:06,430 production and the backup systems. 637 00:32:07,040 --> 00:32:10,850 And even if I was using a SaaS service that said it had 638 00:32:10,860 --> 00:32:12,540 SaaS, or said it had backup. 639 00:32:13,620 --> 00:32:18,250 I would need a really good reason to use that service. 640 00:32:18,600 --> 00:32:24,310 it would be so much easier for me in terms of to feel better, to back 641 00:32:24,310 --> 00:32:26,440 that up to a different service. 642 00:32:27,135 --> 00:32:30,825 at least that way, again, it's splitting the risk profile, right? 643 00:32:32,290 --> 00:32:35,850 the one other example, I know we don't normally think of it as SaaS, 644 00:32:36,250 --> 00:32:39,810 but I think the Rackspace example with their managed email is actually 645 00:32:39,855 --> 00:32:46,965 Yeah, yeah, I think it might actually be PaaS, because it was hosted 646 00:32:46,965 --> 00:32:53,685 Exchange, but I never, it's somewhere between PaaS and SaaS, right? 647 00:32:54,095 --> 00:32:59,785 because if you're still managing Exchange, Like it's exchange and you're not just, 648 00:33:00,255 --> 00:33:04,015 but if the UI, I never administered, if the UI is basically the same as 649 00:33:04,015 --> 00:33:07,945 365 and you just get the advantages of having all your data in one place, 650 00:33:07,995 --> 00:33:12,445 then it would be, then it would be, that would be SaaS, but, but yeah, 651 00:33:12,700 --> 00:33:13,530 But they were doing their own 652 00:33:13,575 --> 00:33:15,485 they were doing their own backups as well. 653 00:33:15,485 --> 00:33:16,845 And we know how that went. 654 00:33:17,075 --> 00:33:17,715 so 655 00:33:18,300 --> 00:33:20,700 We don't mean to pick on these same companies, but it's 656 00:33:20,700 --> 00:33:22,580 just good learning examples, 657 00:33:22,670 --> 00:33:23,050 for... 658 00:33:23,945 --> 00:33:24,355 right? 659 00:33:24,765 --> 00:33:29,675 And yeah, if you don't want me to name you as an example, uh, 660 00:33:29,695 --> 00:33:31,935 then don't, don't do bad stuff. 661 00:33:32,935 --> 00:33:33,385 Back up your 662 00:33:33,740 --> 00:33:34,760 Bag of your data. 663 00:33:34,900 --> 00:33:35,220 Yeah. 664 00:33:35,220 --> 00:33:38,390 If you don't want to be the next example that I talk about on some 665 00:33:38,390 --> 00:33:44,391 future episode of, this podcast, then, just don't do that stuff. 666 00:33:44,391 --> 00:33:46,291 So summary statement, Prasanna. 667 00:33:46,401 --> 00:33:48,251 All cloud stuff needs to be backed up. 668 00:33:48,641 --> 00:33:49,921 Any problems with that statement? 669 00:33:50,591 --> 00:33:51,051 Okay. 670 00:33:51,681 --> 00:33:53,071 And then what do we want to do? 671 00:33:53,071 --> 00:33:55,171 We want to make sure that we separate. 672 00:33:56,036 --> 00:33:59,196 The backups from the primary as much as possible. 673 00:33:59,226 --> 00:34:01,656 And I talk about a different region and a different account. 674 00:34:02,186 --> 00:34:05,056 and then You brought up a really good point of making sure that backup, 675 00:34:05,296 --> 00:34:07,186 because again, now this is your core. 676 00:34:07,186 --> 00:34:10,356 It's your, you know, it's the, the golden goose and the egg, right? 677 00:34:10,766 --> 00:34:16,366 So make sure that you've locked that down as much as you possibly can. 678 00:34:17,106 --> 00:34:18,296 I was thinking about this. 679 00:34:18,346 --> 00:34:20,976 You know what we should be calling that thing? 680 00:34:21,566 --> 00:34:24,796 You know how they have that seed vault in... 681 00:34:24,806 --> 00:34:25,316 where is it? 682 00:34:26,251 --> 00:34:31,311 Somewhere in, the Arctic region, where they have, like, all these seeds for 683 00:34:31,336 --> 00:34:32,116 yeah, yeah, yeah. 684 00:34:32,156 --> 00:34:34,406 The, um, give me a second. 685 00:34:34,406 --> 00:34:37,541 It's, um, Heirloom, the heirloom seed ball. 686 00:34:37,631 --> 00:34:37,981 Yeah, 687 00:34:38,921 --> 00:34:42,111 Yeah, so that, that's what this should be, right? 688 00:34:42,241 --> 00:34:47,591 This is literally the last copy of all your data for your entire company, right? 689 00:34:47,621 --> 00:34:49,471 You want to preserve it just like that. 690 00:34:49,621 --> 00:34:50,281 exactly. 691 00:34:50,411 --> 00:34:51,031 Exactly. 692 00:34:51,061 --> 00:34:51,301 Yeah. 693 00:34:51,301 --> 00:34:54,301 That's a, people probably don't know about that, but basically, an heirloom 694 00:34:54,751 --> 00:35:00,171 seed is an unmodified original, thing and the somewhere, somebody is 695 00:35:00,171 --> 00:35:02,921 storing seeds for all these things. 696 00:35:03,531 --> 00:35:03,921 just in 697 00:35:04,151 --> 00:35:05,231 It's across the world, 698 00:35:05,231 --> 00:35:05,551 yeah, 699 00:35:05,891 --> 00:35:07,601 a nuclear disaster or something. 700 00:35:08,371 --> 00:35:09,381 this has been a good episode. 701 00:35:09,381 --> 00:35:14,241 hopefully you've, uh, learned a lot about, backing up cloud resources. 702 00:35:14,241 --> 00:35:24,051 The first of, let's see, the first of like three different, um, modern things 703 00:35:24,051 --> 00:35:29,101 that need to be backed up and, um, any final thoughts on that, Prasanna? 704 00:35:30,101 --> 00:35:35,241 I think the final thought would be, just because it runs in the cloud doesn't 705 00:35:35,241 --> 00:35:36,681 mean you don't need to back it up. 706 00:35:37,171 --> 00:35:40,411 Ask the question, how are you protecting your data and where is it going? 707 00:35:40,821 --> 00:35:41,171 Yeah. 708 00:35:41,951 --> 00:35:42,871 Couldn't have said it better. 709 00:35:43,621 --> 00:35:45,671 so anyway, thanks a lot, Prasanna. 710 00:35:46,671 --> 00:35:47,561 Thank you, Curtis. 711 00:35:47,571 --> 00:35:48,571 Always fun, always a 712 00:35:48,691 --> 00:35:49,631 Always fun. 713 00:35:49,731 --> 00:35:53,361 I want to thank you for listening to this episode of the backup wrap-up. 714 00:35:53,721 --> 00:35:55,221 It is an independent podcast. 715 00:35:55,221 --> 00:35:58,581 And any statements made are the opinions of the speaker and 716 00:35:58,581 --> 00:36:00,231 not necessarily their employer. 717 00:36:00,861 --> 00:36:05,041 Be sure to check out our other episodes on backupwrapup.Com. 718 00:36:05,511 --> 00:36:10,551 Our YouTube channel by the same name, or of course, wherever you get your podcasts.