Shirt Pocket Discussions  
    Home netTunes launchTunes SuperDuper! Buy Now Support Discussions About Shirt Pocket    

Go Back   Shirt Pocket Discussions > SuperDuper! > General
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Rate Thread Display Modes
  #1  
Old 03-10-2016, 01:45 PM
Argent Argent is offline
Registered User
 
Join Date: Nov 2005
Posts: 4
Solution for the new ransomware on Macs

I see that Transmission for Mac has been infected with ransomware. Yikes. I don't use Transmission, but if it happened there, other apps will be next. It was said that the only solution is to store backups offline, because all flies online will be encrypterd. What about using
"On successful completion -> Eject [drive]"?

My question is, will SD remount the drive before the next backup?
Reply With Quote
  #2  
Old 03-10-2016, 02:13 PM
dnanian's Avatar
dnanian dnanian is offline
Administrator
 
Join Date: Apr 2001
Location: Weston, MA
Posts: 14,923
Send a message via AIM to dnanian
Yes, it'll automatically mount and unmount when done (on a schedule).
__________________
--Dave Nanian
Reply With Quote
  #3  
Old 06-23-2016, 07:20 PM
flyingout flyingout is offline
Registered User
 
Join Date: Jun 2008
Posts: 9
Hi Dave,

Reviving this thread since my goal is also to mitigate against ransomware.

I think I know the answer but figured I'd ask just in case.

I don't believe mounting and unmounting is sufficient since if SD can do it, so can the bad guys. So my thought was to remove the destination's FileVault password from the keychain, and mount it using a script, which I wrote. Unfortunately I found out that the before copy script doesn't run until a destination is available.

I suppose I can schedule my script separately, but that's more prone to problems.

So any thoughts on how this can be done? Might SD be able to ask for and hold onto the PW?

Thanks
Reply With Quote
  #4  
Old 06-23-2016, 09:18 PM
dnanian's Avatar
dnanian dnanian is offline
Administrator
 
Join Date: Apr 2001
Location: Weston, MA
Posts: 14,923
Send a message via AIM to dnanian
Just use two backups, one of which is connected and one of which isn't. Also, have an offsite backup with something like CrashPlan, Backblaze or the like.
__________________
--Dave Nanian
Reply With Quote
  #5  
Old 06-24-2016, 01:31 AM
flyingout flyingout is offline
Registered User
 
Join Date: Jun 2008
Posts: 9
Quote:
Originally Posted by dnanian View Post
Just use two backups, one of which is connected and one of which isn't. Also, have an offsite backup with something like CrashPlan, Backblaze or the like.
Thanks Dave. Exactly my setup. For as long as they've been available I've had TM, online clone, and Arq to S3. Now I've added an offline clone. I'm just trying to automate that offline one, because lazy.

I think I found a solution though. I'll schedule my unlock/mount script(s) separately and have SD do the copy automatically upon attachment.

The only thing is that I've also got a couple external volumes that I'll probably now want to encrypt and detach their backups. So I'll be losing SD's simple scheduling ability completely.

Cheers
Reply With Quote
  #6  
Old 06-24-2016, 06:49 AM
dnanian's Avatar
dnanian dnanian is offline
Administrator
 
Join Date: Apr 2001
Location: Weston, MA
Posts: 14,923
Send a message via AIM to dnanian
You can: just put the password in the keychain and use "Backup on connect".
__________________
--Dave Nanian
Reply With Quote
  #7  
Old 06-24-2016, 05:38 PM
flyingout flyingout is offline
Registered User
 
Join Date: Jun 2008
Posts: 9
Quote:
Originally Posted by dnanian View Post
You can: just put the password in the keychain and use "Backup on connect".
Well, I'm taking a big step back to figure out exactly how FileVault, Disk Utility (and diskutil), Keychain (and its Access Control) work. I'm at a loss at the moment.

Ejecting doesn't appear to relock the volume. And when locked (how?) Disk Utility and SD can't mount it, despite Keychain.

If ejecting would consistently lock the drive and Keychain's Access Control only gives the password to applications I allow (i.e. not to malware) then I'd be good. Not seeing that right now.

Cheers
Reply With Quote
  #8  
Old 06-24-2016, 06:01 PM
dnanian's Avatar
dnanian dnanian is offline
Administrator
 
Join Date: Apr 2001
Location: Weston, MA
Posts: 14,923
Send a message via AIM to dnanian
If you eject it (don't lock it), and try attaching it to another Mac, you'll see it's locked for anyone else.
__________________
--Dave Nanian
Reply With Quote
  #9  
Old 06-24-2016, 06:13 PM
flyingout flyingout is offline
Registered User
 
Join Date: Jun 2008
Posts: 9
Quote:
Originally Posted by dnanian View Post
If you eject it (don't lock it), and try attaching it to another Mac, you'll see it's locked for anyone else.
Right. No question about that. And if I power off and on, it either mounts automatically or asks for the password depending on if there's a keychain entry. This is how I've used FileVault up till now.

But I want some protection against malware (if it were to strike; I'm not hugely concerned btw) by ejecting the volume (one of many on a firewire chain) and know that only trusted apps can remount it. I'm not seeing that right now.

Either anything can remount it or nobody can. Still figuring out why or what I'm doing wrong.
Reply With Quote
  #10  
Old 06-24-2016, 06:16 PM
dnanian's Avatar
dnanian dnanian is offline
Administrator
 
Join Date: Apr 2001
Location: Weston, MA
Posts: 14,923
Send a message via AIM to dnanian
If you're really worried about this, just unplug it. Can't mount it if it's not attached.

The best protection against this kind of thing is kind of to just uninstall Flash, keep your OS up to date, and not do dumb things...
__________________
--Dave Nanian
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Multiple Macs in house - SD to NAS??? MacAfrican General 3 08-05-2010 03:37 PM
using SD to back up macs to HP MediaSmart Server banjomensch General 1 04-13-2009 08:59 AM
Newbie: b/u 2 Macs and an external drive? Theophan General 4 09-07-2008 02:16 AM
One license, several Macs? jpgoldberg General 7 01-18-2008 12:46 PM
Help? Qs: Backup over 2 FireWire Netw'd Macs SuperDuperUser General 2 12-29-2006 05:11 PM


All times are GMT -4. The time now is 05:13 PM.


Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2024, vBulletin Solutions, Inc.