4 ms·
To do it properly you would likely be looking at mandatory access control, such as SELinux, so that the ransomware wouldn't be authorized to modify the files an
by idealhavoc 9y ago
To do it properly you would likely be looking at mandatory access control, such as SELinux, so that the ransomware wouldn't be authorized to modify the files and further would make itself obvious in the logs.
Not very easy to use (in a way that still provides meaningful security) outside of the server space, though it can be done.
- kakarot 9y agoRHEL products, including Fedora, come with a fairly usable SELinux out of the box. By extension, so does Qubes OS. I currently run a QEMU setup at home with different VMs, all Fedora, for different domains of use (internet, work, development/art, untrusted, a clean environment for installing OS's, etc) in the spirit of Qubes. Regular backups of everything are made frequently. In the highly unlikely event of a ransomware infection, it would be limited to a single domain. I believe this is the way forward for personal computing.