Supported by Fastmail
Sponsor: Fastmail

Fast, private email hosting for you or your business. Try Fastmail free for up to 30 days.

Building a ‘Ransomware-Resistant’ Backup System

Jason Self on backups and ransomware and “Treating Your Data Like a VIP”:

If a machine gets infected with malware while the backup drive is plugged in, your backup is encrypted along with your primary files.

The smarter approach is to dedicate a single, physical machine on the LAN to act as a centralized backup server. […]

This centralized local server is the foundation. But just having a server isn't enough to stop a modern threat. We have to trap the server in a cage.

I’ve never given much consideration to a ransomware attack, but I’m rethinking that now. Some of Self’s advice (tape backups, for example) will be absolute overkill for many people, but there are several very useful recommendations, including limiting SSH to specific (backup-related) commands and “air gapping” your backup server. It also reminded me I really do need to re-add a centralized backup server to my home network.

⚙︎

Subscribe to JAG’s Workshop to get new posts by email, and follow JAG’s Workshop using RSS, Mastodon, Bluesky, or LinkedIn . You can also support the site with a one-time tip of any amount.