7 ms·
To add to this: having the backups copy somewhere that has write-only permissions can be a life-saver in a crypto-ransom malware situation. Hackers are smart en
by muttled 4y ago
To add to this: having the backups copy somewhere that has write-only permissions can be a life-saver in a crypto-ransom malware situation. Hackers are smart enough to delete or encrypt backups, and this is made far easier for them when admins have full read/write permissions to the backup location.
- bombcar 4y agoOffline backups are very important - not only because they can't be modified because they're disconnected, but because they force you to spend time going and getting them and that time can be important. Many backups are successfully destroyed in trying to back them up, and spending some time to think about what is happening can be worth it.
- SahAssar 4y agorsync.net is great for this. They keep ZFS snapshots, so even though you have read/write access you will always have the snapshots stored. So you will be safe at least as long as you notice the corruption within the normal 7-day rolling window (there are options for other windows or manual snapshots too IIRC). This should also lead to the question of how up-to-date your backups need to be and is your solution setup for that (is it 1s, 1m, 1h, 1d, etc.)? Define an actual SLA for how much data you can loose and test for that.
- Noumenon72 4y agoDoes "write-only permissions" somehow imply they can't overwrite the backup with an encrypted copy? I don't understand how read permissions would allow them to delete or replace something.
- WalterBright 4y agoYeah, it's a crying shame that hard drives no longer come with physical read-only switches. I have no idea why major drive users don't demand this from the makers.
- dsr_ 4y agoAt the desktop level, this would result in a whole new class of useless support calls. At the SOHO server level, this might be useful. But the alternatives are already available: unmount the disk, or unmount and unplug it, or unmount, unplug, and carry over to the safe, or unmount, unplug, and carry to the backup site... At the datacenter level, nobody has time to physically touch things.
- WalterBright 4y agoIf your drive is write-enabled, and you carry it over to your system to restore from backup, then the ransomware can intervene and encrypt it first. Besides, for the bozos, ship the drives with the write-enable turned on. They won't notice the difference.
- justin_oaks 4y agoThe solution for this that I've been working with is having an S3 bucket with versioning enabled. The systems that send backups to that S3 bucket don't have permissions to modify previous versions. If one or all of those systems are compromised then they can't overwrite previous backups because the original data will still exist in old versions.