Yeah, but to read the backup you've got to attach it to your compromised system. Boom, it's corrupted.
A physical read-only switch is required.
A physical read-only switch is required.
Not ironclad but pretty good. Issues with it that first come to mind are the live operating system image was already compromised when it was written to say the USB disk, or compromised firmware, and of course user error (nothing to do with ransomware in this case). I am not familiar with this stuff so I may be missing something very important, if so tell me about it.
Just think of all the security issues that would just go away with physical write-enable switches.
Heck, I'd go further, and demand from disk makers a physical write enable switch for a separate volume. Use that volume for the system software.