borgbackup / borgbackup/borg

Consider deprecating `init -e none` now and removing it with Borg 2

Open
#9,104 21 comments 0 reactions 0 assignees View on GitHub
cmd: init / repo-create
Dominant language
Python
Stars
13.7k
Forks
875
Avg merge
11h 15m
Merged PRs (30d)
192

Description

/kind discussion

This issue exists to get some feedback whether deprecating `init --encryption none` now and removing it with Borg 2 is feasible.

Prior discussion see https://github.com/borgbackup/borg/issues/9072#issuecomment-3446729458

Since version 1.1 Borg supports the `authenticated` mode as an alternative to `none` mode: Contents are stored unencrypted, but authenticated using the HMAC-SHA256 hash. This protects users from accidental or malicious attempts to tamper with the repo, including denial-of-service attacks against clients. That's why `authenticated` mode is recommended over `none` mode since Borg 1.1 and `none` mode is discouraged for new repos, but still fully supported.

Since Borg 2 requires users to `transfer` their Borg 1 archives over to a new Borg 2 repo anyway, I think this is the best time to remove `none` mode if we actually consider it obsolete. AFAIK `transfer` requires rechunking then. The idea is to officially deprecate `none` mode now and remove it with Borg 2 (with the exception of `transfer --from-borg1`), users really should use something else (either `authenticated`, or `repokey` / `keyfile` with an empty passphrase).

I'm not 100% convinced about this idea yet either, but some feedback and a discussion about it might clarify things.

Open question for our encryption experts: What are the implications of using an empty passphrase with `authenticated` mode?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.