3 ms·
How do you guard against cryptolockers?
by solstice 6y ago
How do you guard against cryptolockers?
- Delk 6y agoI'm not who you responded to, but my incremental backups on an external HDD probably always date back at least half a year (seems to be a little over a year at the moment, limited by disk space). I don't know if that's enough to guard against cryptolockers, but it seems enough to me. (Being on Linux also makes me probably a less likely target for cryptolockers, but that's not the case for everyone.) It would be good to have a second backup in case the backup HDD fails, of course.
- lytefm 6y agoExactly. Well, perhaps there is some evil kind of cryptolocker that will wait until the external HDD of my Linux laptop is plugged in before it encrypts everything. Hasn't happened to me yet, but I've crashed my external HDD once, a second backup definitely makes sense.
- solstice 6y agoAfaik that's exactly what these cryptolockers often do: after infecting a system they start encrypting things while sitting between the user and the OS to transparently forward file access. This also goes for any accessible network drives and external disks that are connected. Then, after a certain time has elapsed (or whatever other metric the malware author has chosen) the cryptolocker stops forwarding file access and holds you ransom. In that scenario, if your backup drive is writeable from your infected machine, your backups are potentially fucked. One way to guard against this would be for example a raspberry pi on your network that periodically connects to your (possibly infected) main machine and makes incremental copies over the network to an external HD connected to the Pi. (Meaning the Pi reads and determines what is new, what's is old and how to make the incremental backup.) This of course needs to be coupled to some sort of smart versioning scheme and regular inspection of the backups by the user.