| ▲ | computator 4 hours ago | |
Blu-ray, or any non-rewritable optical media, guarantees that it hasn't been tampered with. If I were attacked by malware, I like the confidence that the Blu-ray backup is absolutely guaranteed to be the same as on the date it was written. A hard disk used for backup might have been reattached to the network at some point after the initial backup and gotten infected/corrupted/altered. | ||
| ▲ | Terr_ 4 hours ago | parent | next [-] | |
> Blu-ray, or any non-rewritable optical media, guarantees that it hasn't been tampered with. In terms of external tampering, I think that need is better-served by encrypting everything, which you probably want to do anyway. Or at least using some sort of checksum signed by a key. However if the focus is "what if the backup process is compromised", then yes, having some date which is beyond its writing-reach may be useful. Another aspect of this might be a remote-backup system where one set of credential is enough for daily backups and restore, while another is needed in order to access a set of older duplicates that are remotely maintained as ransomware-protection. | ||
| ▲ | taneliv 2 hours ago | parent | prev [-] | |
That depends on your threat model. If the attacker can swap the Blu-ray disc to a similar looking one, but with content they control, that absolute guarantee becomes moot. | ||