4 ms·
If you are not modifying/editing the files (just reading them) and you run Linux, then do this: 1. Don't allow users to sudo. 2. chmod the files to 400 (read-
by _wldu 4y ago
If you are not modifying/editing the files (just reading them) and you run Linux, then do this:
1. Don't allow users to sudo.
2. chmod the files to 400 (read-only) as the normal user.
3. chattr +i the files (as root) to prevent modifications. This makes the files immutable (cannot be changed).
So if ransomware (running in the context of a normal user) gets onto the machine, it cannot encrypt the files.
Hope this helps.
- assttoasstmgr 4y agoI don't think this would be effective honestly. The theory behind ransomware is that it attacks data of value to you, which you are typically reading and writing. It's uncommon that data is written once then never modified. Restricting sudo won't stop local privilege escalation exploits and those are all too common under Linux. Mounting /usr ro as a separate filesystem is likely much easier than some of the steps described. But again, who cares if the OS is trashed? You just reinstall from media. It's the data you care about. A layered approach is warranted and there isn't a simple list of tips to accomplish what OP wants.