Ask HN: How do you guard against ransomeware? (offsite backups not possible)
What are some ways you have prepared for ransomware?
I've thought about:
1) udev rules that blacklist drives until the infrequent moments I do full backups
2) a "USB condom" of sorts that I can remotely disconnect (sever the 5V line), to make a USB spinning HD available as needed with an authentication scheme
3) running a program that tries to detect ransomware execution (antivirus or excessive cpu usage/encryption/etc)
4) mirror it to the cloud (unworkable, considering it's 16TB)
I don't think there's a solution as good as offsite backups. Most of these are ideas that add indirection or complexity that common ransomware wouldn't be coded for.
How do you disconnect a drive without disconnecting it? Especially nvme rather than a USB enclosure?
What is your creative solution?