5 ms·
Apple puts so much pressure on security, shouldn't it be possible to block ransomware somehow on the OS level, possibly on all platforms? I mean not many apps
by b212 6y ago
Apple puts so much pressure on security, shouldn't it be possible to block ransomware somehow on the OS level, possibly on all platforms?
I mean not many apps need to modify millions of files on all drives including network drives and dongles... It should be fairly easy to spot, something like:
1. If xxx wants to modify more than 50 files in 24 hours go to 2.
2. If some of the files were modified more than a week ago or if the files are in directories across multiple drives go to 3.
3. If some of the files are images/documents it's a no go, prompt user to accept and list the affected files.
I'd love something like this for my Synology, it's connected to my Macbook as a network drive and I store my backups there, if anything modifies these files without my knowledge I'm doomed. I need to access some of my backups on daily basis so it's kinda hard to disconnect te drive all the time :/
- giancarlostoro 6y agoYou may want to consider archiving some of those backups to an external drive that is only hooked up to store new data maybe? Or maybe theres something you can do for the network drive
- cutemonster 6y agoAppend-only external disk, is there sth like that? And one flips a hardware switch to start overwriting from the beginning, if disk full
- giancarlostoro 6y agoI think a network based one in theory should be capable of doing so with the right OS / configuration, but not sure about a hardware based one https://en.wikipedia.org/wiki/Write_once_read_many https://en.wikipedia.org/wiki/Write_once_read_many This is the acronym I saw on HN somewhere though, WORM. Edit: Upon further research its kind of annoying that this isn't more common for NAS / cloud storage solutions. I think some like Dropbox do keep revisions on the other hand.
- cutemonster 6y agoSyncthing can save revisions, and is open source -- I remember now https://docs.syncthing.net/users/versioning.html https://docs.syncthing.net/users/versioning.html Lots of config options
- auxym 6y agoConsider replicating your Synology to a cloud service. Ransomware isn't your only risk here, burglary or fire could also leave you without your backups.
- aj3 6y agoWindows 10 has just what you describe: https://www.bleepingcomputer.com/news/microsoft/how-to-enable-ransomware-protection-in-windows-10/ https://www.bleepingcomputer.com/news/microsoft/how-to-enabl... Of course, bad guys still can 1) create encrypted copy and delete originals instead of modifying files in place; 2) disable protection alongside with A/V and proceed as usual; and my favorite 3) rely on built-in disk encryption mechanisms and simply overwrite encryption keys & salts.
- vladvasiliu 6y ago> Windows 10 has just what you describe [link] I've looked into this, but it feels limited to me. It's all or nothing. I can't have App1 only access Documents and App2 only access Pictures. Once I give any one app access to the "protected folders", it has access to all the protected folders.
- aj3 6y agoYes, it's does not give you SELinux/seccomp level of granularity. But then again, there is a slight chance that users might actually understand what it's for and how to use it, unlike SELinux/seccomp. In practice though, if you're a power user you probably won't run shady binaries, and if you do - nothing will protect you from them as your user is likely a member of administrative group / wheel and you use sudo/su/doas somewhat regularly. While if you're worried about protecting your employees/family members, just making sure they are not part of the same admin groups and enforcing basic Software Restriction Policy / AppLocker / SELinux / RBAC will be enough to protect against 99% threats out there.
- vladvasiliu 6y agoI agree that SELinux is much too complex for "regular people". However, the issue I see with this approach is that the default location for saving pretty much everything on Windows is the Documents folder. So I think most people would just blindly agree to give access to this folder. Most malware comes from apps people wilfully install, so they would probably grant them access to the folders because they would want to use them. The approach I like best is what MacOS does, where you have to approve access to a specific folder. The drawback of the MacOS implementation is that I cannot define specific folders I want protected (say .ssh).
- Lex-2008 6y agoJust out of curiosity, can you clarify on "I need to access some of my backups on daily basis"?
- jedieaston 6y agoTime Machine (I don't know if that is what they are talking about, but it's an example) is designed to be used daily as well as in case your laptop explodes. Opening Time Machine allows you to go back and see every version of a file as long as your backup drive was connected when you saved it.
- robert_g 6y agoJust quickly thinking of where there might be a lot of images/documents modified quickly: web browser cache, photo management software, antivirus software. I think it'd be easier to isolate applications and data like Cubes OS instead of trying to create a universal rule set. https://www.qubes-os.org/intro/ https://www.qubes-os.org/intro/
- _wldu 6y agoRead only filesystem snapshots (that can be restored quickly) are the best way to prevent ransomware IMPO. The snapshots can't be over-written or modified and the user can restore them whenever they like.
- theandrewbailey 6y agoThis is why offline backups are important. Ransomware can't do anything with a drive that isn't running. Having an external hard drive that you need to physically plug and unplug once/twice/etc a week might sound inconvenient, but it solves your potential issue.
- 14 6y agoAre there any versions of malware that sit and wait for several months so that once you have it in your backups it sits and waits for you to save over your old back up and then starts it’s thing? Then if you restore from that backup you have the malware sitting waiting again to start.
- cutemonster 6y agoCan that be worked around by having extra backups with only non executable files? Like txt, png, cpp (but without compiling and running)? I have a vague memory of ransomware that waited for one to mount external disks yes, but not as advanced as they ones you mentioned
- vladvasiliu 6y agoHow would that work? If it didn't encrypt your active storage, then the backups wouldn't be encrypted either, right? Or would it somehow interfere with the backups, making you think the backup's OK when it actually is just garbage and then encrypt your active drive when no more usable backups exist? I guess that's one reason why if you don't try restoring from you backups it's as good as not having any...
- leokennis 6y agoYep: - External drive with a bootable backup (Carbon Copy Cloner) - Network drive with automagical Time Machine backups - Offsite versioned backups (for example Backblaze) "Pride goes before destruction, and a haughty spirit before a fall", but I'd be surprised if I ever will lose a file like this.
- deleted 6y ago[deleted]
- yonixw 6y agoSo each NPM\YARN install will fail... We need an API that we can extend as much as we want...
- cutemonster 6y ago> each NPM\YARN install will fail No -- that only writes to sub dirs
- sneak 6y agoThe current macOS already has great ransomware protections in the form of per-app, per-directory file access permissions. Don’t let apps access “files on external volumes” or “files on removable media” or whatever it calls it on the popup when an app first tries to access those.
- jeanofthedead 6y agoThere's a fantastic free tool called RansomWhere by Objective-See that I use to monitor the rapid creation of encrypted files on my Mac. It notifies me from time to time during installation processes that something possibly malicious is going on. Link: https://objective-see.com/products/ransomwhere.html https://objective-see.com/products/ransomwhere.html
- copperx 6y agoIs there anything like this for Windows, where most ransomware thrives?