3 ms·
Though btrfs snapshots are writable, at least by default, right?
by Rovanion 11y ago
Though btrfs snapshots are writable, at least by default, right?
- leni536 11y agoThat's not really the point. Your btrfs file system to be an effective measure against attack should be on a separate machine where you only have write access to one single snapshot. If you have btrfs on your working machine it's not effective. Once someone gets root then they can just unmount it and encrypt the raw device. The point is privilage separation and if you want to protect against root exploits then you need a separate machine with appropriate access control (which is basically an append-only backup).
- XorNot 11y agoCryptolocker doesn't get root though - that's the point. Cryptolocker exploits the absurd situation that we protect system data better then we protect user data - the irreplaceable part of your computer. ZFS protection on Linux is also an accident here - because on Solaris users can manage their own snapshots, but in ZoL you currently need root. I've said it before: what people need is the concept of user privilege namespaces. So you sudo elevate yourself into 'backup' privileges without elevating to root.