Hacker News new | ask | show | jobs
by jupiter909 1857 days ago
One can do ZFS snapshots so one does not need do insanely huge backups all the time. Just transfer off the diffs as needed. If an attack happens it's pretty easy to roll-back to a known good state. It's also not that complex to set some process in place that does random checksum verification of some files to trigger an alarm that such an attack has taken place. It is really perplexing me that very large institutes don't do this
2 comments

Large institutions aren't solving their security problems by hiring a small clutch of FreeBSD elves.

They're hiring consultants to confirm that they've met the requirements of some checklist, which requirements may include "have a plan to fix this obvious problem.... someday. You do? OK, then you're fine". That's much cheaper and is 100% management-class controlled.

Snapshots, RAID, etc are not substitutes for backups