Re: Backing Up



Arno Wagner <me@xxxxxxxxxxx> wrote:
Previously sam <sambo@xxxxxxxx> wrote:
Arno Wagner <me@xxxxxxxxxxx> wrote:
Previously sam <sambo@xxxxxxxx> wrote:
Arno Wagner <me@xxxxxxxxxxx> wrote:
Previously mscotgrove@xxxxxxx <mscotgrove@xxxxxxx> wrote:
On Apr 1, 12:57 pm, Arno Wagner <m...@xxxxxxxxxxx> wrote:
Previously mscotgr...@xxxxxxx <mscotgr...@xxxxxxx> wrote:
On Apr 1, 3:17 am, "iws" <nos...@xxxxxxxxxx> wrote:
"Matt" <matt...@xxxxxxxxxxx> wrote in message
[...]
If you trust Carbonite (and you have to, despite their claims
of encryption, after all it is their software doing the
encryption), and you only need backups under Windows, it looks
like a good deal.

Arno- Hide quoted text -

- Show quoted text -

If you are really worried about security, you can encrypt your
files first. It would be an extra stage, but if really
worried/concerned/ paronoid, very possible. Carbonite only backs
up files / directories you want to to.

Personally, I am the only person interested in my (excellent)
holiday photos.

Well, for the really paranoid, this is again not enough,
since you are running their software on your system.

Its easy to ensure that it cant do anything that matters to the
system its run on.

I don't think so.

You're wrong.

Local attacks that allow privilege elevation are notoriously easy
on Windows.

And its easy to check whether that is happening, and easy to
ensure that they cant do any damage to the system that its run on.

And even if you put it into a virtual machine, there
have been vulnerabilities, that allowed breaking out.

And its easy to check whether that is happening, and easy to
ensure that they cant do any damage to the system that its run on.

Oh, so fighting malware is easy?

Yep, if you know what you are doing.

I hadn't noticed. Better get rid of that anti-virus company stock fast....

Thats what you use to protect against malware.

Honestly, neither of the two taks is easy, even for an expert.

Wrong.

The things that may prevent this attack is not that it is hard.
It is that a) it would kill the business if exposed and b) why
would the business invest money into creating this capability?

Sure, but thats a separate issue to whether its perfectly possible to protect against that unlikely possibility.


.



Relevant Pages

  • Re: Protecting sensitive files on a Windows file server
    ... I don't want to sound like a crank here, but why would you not be able to protect these files using standard NTFS/GPO/File permissions on the files? ... I've got some servers with highly sensitive files on them and we've designed the permissions such that only those "need to know" are even aware that they are there, much less can actually gain access to them. ... Encrypted backups help there, in case of lost media, but when it comes to windows, that nut is hard to crack. ... Commerical encryption may be the choice, but then again, you have to give the keys out to those that "need" to gain access to these files. ...
    (Security-Basics)
  • Re: PASSWORD
    ... It's not necessary to use encryption to limit access to a drive. ... Permissions to access folders on a drive are all that need to be used. ... Set, View, Change, or Remove File and Folder Permissions in Windows ... You can use a screensaver password to protect your ...
    (microsoft.public.windowsxp.basics)
  • Re: cant encrypt/turn off read-only
    ... Only Windows XP Professional has the File Encryption System. ... Protect your PC! ... | C drive itself - a filled read-only checkbox. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Folder password protection
    ... But encryption is the only thing that can protect you. ... > I am using Windows XP professional on my laptop and I am always worried ... > about my laptop gets stolen and I am wondering if its possible that I can ...
    (microsoft.public.windowsxp.newusers)
  • Re: Securing data to a process principal
    ... reasonable controls that protect against "casual" abuse. ... hooks into your encryption function) and you cannot prevent an admin using ... The RM analyst also uses an app that has an embedded obfuscated key (I'll ... where the secret is stored in the registry. ...
    (microsoft.public.platformsdk.security)