3 ms·
+1 for the Pi. I'm in the middle of tweaking BackupPC [1] on Slackware in one of these so it will regularly pull updated files from the handful of Windows mach
by dbtx 7y ago
+1 for the Pi.
I'm in the middle of tweaking BackupPC [1] on Slackware in one of these so it will regularly pull updated files from the handful of Windows machines, and ransomware won't be able to know it exists. The only thing on each Win box is a cygwin-powered rsync daemon; it doesn't need write access to any outside filesystems or services.
In the back of my mind, I think it could be used to set up a sort of tripwire for the presence of ransomware-- lots of files would be changed in a short time (unless said RW also decrypts them all silently and transparently on access, until the time comes to drop the ax on you-- that would only defeat the tripwire and most if not all of the files would be still saved in old backup sets anyway). Since it only stores identical files once, the change in space required for a single full backup will suddenly jump, and all you'd need is one automated email alert like the others.
Sorry that the thing doesn't actually do its job yet and I haven't likewise written anything up :(
[1] https://backuppc.github.io/backuppc https://backuppc.github.io/backuppc
- dbtx 7y agoAt the same time, there's a 'hosts allow' directive with the Pi's IP in the rsync config stored on each Win box, so it's not really invisible. Also, someone might save the password to the BPC web frontend in their browser, so a sufficiently clever RW could still wreck everything here. I hope it's just that the web server needs some 2FA/OTP.