this post was submitted on 18 Feb 2025
200 points (100.0% liked)

Not The Onion

13644 readers
785 users here now

Welcome

We're not The Onion! Not affiliated with them in any way! Not operated by them in any way! All the news here is real!

The Rules

Posts must be:

  1. Links to news stories from...
  2. ...credible sources, with...
  3. ...their original headlines, that...
  4. ...would make people who see the headline think, “That has got to be a story from The Onion, America’s Finest News Source.”

Comments must abide by the server rules for Lemmy.world and generally abstain from trollish, bigoted, or otherwise disruptive behavior that makes this community less fun for everyone.

And that’s basically it!

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Nougat@fedia.io 9 points 5 days ago (1 children)

Depends on the needs of the business, of course, but --

There are lots of different ways to make data rollback robust, and as many methods as possible will offer different avenues to recovery. VM snapshots (with or without live mounting), shadow copies, incremental forever, cloud storage for backups, multiple appliances in different physical locations.

None of these are terribly "difficult." What tends to make these kinds of efforts less effective is a failure to regularly test them. Can I recover a VM snapshot? Can I live mount it somewhere? Sure, the product I'm using says I can, but have I proved it, and do I still remember how to do it quickly and correctly in the middle of a crisis?

[–] IHawkMike@lemmy.world 5 points 4 days ago (1 children)

Nothing you said is wrong, in fact it's all good advice. But none of what you listed implicitly provides protection against ransomware either.

For that you need backups that are immutable. That is, even you as the admin cannot alter, encrypt, or delete them because your threat model should assume full admin account compromise. There are several onprem solutions for it and most of the cloud providers offer immutable storage now too.

And at the very least, remove AD SSO from your backup software admin portals (and hypervisors); make your admins use a password safe.

[–] Nougat@fedia.io 3 points 4 days ago

You're right, I forgot about that. Our backups require three people's signoff to delete. Alter and encrypt I'm sure are the same, we've just never needed to do that as far as I'm aware.