Hi Dave,

Reviving this thread since my goal is also to mitigate against ransomware.

I think I know the answer but figured I'd ask just in case.

I don't believe mounting and unmounting is sufficient since if SD can do it, so can the bad guys. So my thought was to remove the destination's FileVault password from the keychain, and mount it using a script, which I wrote. Unfortunately I found out that the before copy script doesn't run until a destination is available.

I suppose I can schedule my script separately, but that's more prone to problems.

So any thoughts on how this can be done? Might SD be able to ask for and hold onto the PW?

