16 ms·
There are USB drives that do vaguely similar things but it's all in software. It's difficult to do that unless the filesystem has append only functionality, met
by netflixandkill 6y ago
There are USB drives that do vaguely similar things but it's all in software. It's difficult to do that unless the filesystem has append only functionality, metadata blocks are rewritten all the time even if data isn't.
For anyone who has serious (I.e. $$$) need of that they already have tapes and optical WORM media though.
You can do something conceptually similar with any sort of NAS that provides immutable snapshots as long as the management and control is effectively out of band.
The out of band part is the key. Our SAN data has snapshots. The backups are written to another storage device that only has an API key to write them to B2 storage. An attacker would effectively need to completely compromise multiple admins in the organization to get at all the stages of data duplication, and frankly there is no additional line of defense for total compromise if the attacker is willing to wait for physical tape or disk swaps.
Fortunately for ransomware, time is money for them too.
- EvanAnderson 6y agoAre there any NAS devices with out-of-band management actually available, though?
- benjohnson 6y agoSpin up a FreeBSD box, enable ZFS snapshots and disable SSH? You’d only be able to destroy the snapshots from a monitor and keyboard under normal circumstances.
- EvanAnderson 6y agoWell, yeah. I was more asking "does somebody make such a thing purpose-built?"
- WalterBright 6y ago> There are USB drives that do vaguely similar things but it's all in software. Sigh. When are people going to accept that software switches are inherently not secure? How many times must these fail? > It's difficult to do that unless the filesystem has append only functionality, metadata blocks are rewritten all the time even if data isn't. There's no reason to continue writing anything to a hard drive once the backup to it is finished.
- selfhoster11 6y agoA software switch might as well not exist at all. They are not secure, or useful, because they can just be ignored by the host machine.