Defeating CryptoLocker Attacks with ZFS
ixsystems.com
ixsystems.com
However this can be done a million different ways. It's just a backup not accessible to the affected system... I do the same thing with my bare metal OSX machines (macbook, macpro, etc...) they use time machine to backup to Netatalk shares, those shares are image files which again get backed to the ZFS SAN. So even if the time machine share was encrypted I'd have a copy of the image holding the share from X days ago.
Presumably ZFS is immune from CryptoLocker. CryptoLocker can only compromise NTFS 'computers'.
Basically they rely on any kind of backup which is not accessible as an writable file on the currently mounted fs. There's nothing ZFS specific there. That part is just an advertisement for ixsystems + freenas.
The point is privilage separation and if you want to protect against root exploits then you need a separate machine with appropriate access control (which is basically an append-only backup).
ZFS protection on Linux is also an accident here - because on Solaris users can manage their own snapshots, but in ZoL you currently need root.
I've said it before: what people need is the concept of user privilege namespaces. So you sudo elevate yourself into 'backup' privileges without elevating to root.