4 ms·
Users need to be able to edit the same files that ransomware encrypts, and differentiating between a legitimate user and a ransomware program is difficult.
by slang800 6y ago
Users need to be able to edit the same files that ransomware encrypts, and differentiating between a legitimate user and a ransomware program is difficult.
- mikewarot 6y agoIf the backups are made by the system, and the user can't access them, and the system protects itself (and the backups, obviously)... ransomware shouldn't be possible. No matter what the application does, it can't access the backups in such a system.
- chefkoch 6y ago> If the backups are made by the system, and the user can't access them, and the system protects itself (and the backups, obviously)... ransomware shouldn't be possible. And if the gang get's admin rights on the box your backups are gone.
- Ajedi32 6y agoThat's a much higher bar to clear, particularly if end-users don't have admin access to their workstations.
- kemotep 6y agoEspecially since the user is the one being tricked into executing the ransomware.
- mikewarot 6y agoWhy does the user have access to the backups?
- chefkoch 6y agoIf you are an enterprise, they will try to get admin credentials so they can crypt everything, even domain controllers.
- kemotep 6y agoI was speaking in the context of the files, not the backups. How is this program to know that a file edited by the virus to encrypt is legitimate or not when the edit is being made by a user that created and owns those files? The backups themselves can be contaminated months before the encryption and ransomware attack is sprung. Restoring from last week or last month's backup might still lead to your system being encrypted. Additionally, as the other user pointed out the goal would be to gain access to the appropriate user with the level of permissions, such as an admin or root account, and use those credentials to carry out the attack.