Time Machine protects from ransomware?

I read that versioning of backups are the best way to get out of trouble with ransomware, and that Time Machine does just that.


Any advice?

iMac, OS X El Capitan (10.11.1), 16GB RAM, late 2011

Posted on Jun 2, 2017 9:36 AM

Reply
14 replies

Jun 2, 2017 1:35 PM in response to ishrugged

Sorry, in I meant that Apple apparently recommended Malwarebytes, but that's hearsay online (as well as them conflicting). On macOS right now Malwarebytes is only user activated, not running in the background, although a simple Applescript could change that and I have it set to scan whenever I log in (which, admittedly isn't very often).


When I performed a scan just now I found a false positive with an Apple Extension for Safari (from the Apple website) known as "Awesome Screenshot" (https://safari-extensions.apple.com/details/?id=com.diigo.safari.awesomescreensh ot-5DXNM3K2CT) and have reported it to Malwarebytes.


I am looking into maybe flashing my router with Tomato or WRT (likely Tomato if a) my router is supported and b) because I'm a Mac user and GUI is important) as a buffer against other issues, what with backdoors and such being more of an issue in routers from the factory, I think it wise.

Jun 2, 2017 9:53 AM in response to Tesserax

I do, monthly, copy my (encrypted) TimeMachine backup to another HDD via CCC, but that's only monthly, as anything more is unrealistic for me.


These latest crypto-ware lay dormant for days anyway, so a month is likely enough time to look back and picket out, or avoid it, for now? I do have the space for a full thirty days backup.


Any other advice, aside from expensive subscription cloud services?

Jun 2, 2017 10:24 AM in response to macjack

Thanks for the info, I am actively seeking out multiple references, of course the official forums for Apple products is always a reliable place. I mostly wanted to understand "versioning" as I believed at first that I would need a particular RAID configuration, but to learn that Time Machine did it already was encouraging.


I rely on Sophos in the background right now, I'll take a look at Malwarebytes to see what they offer in addition, but am acutely aware of phishing tactics, of course Time Machine being a save-my-backside option, but one I needed to initially better understand.


Thanks for the pointers guys.

Jun 2, 2017 10:32 AM in response to Hamper

The only thing you can rely for Sophos is false positives when it is not causing conflicts with OS X. 3rd party Mac AV products have so far been proven to be ineffective with detecting Malware and Adware on Mac and never actually faced an actual Mac Virus so their reaction to one if it came into existence has never been documented.


If you are using Sophos to protect PC's on your network use a Windows AV product on the Windows device to do that so you are not causing potential and often serious issues.

3rd party Mac AV products have been documented on these forums as points of conflict with OS X/Mac OS's ability to manage itself through the securities updates Apple provides.


Updates to your OS and securities patches from Apple are the single best software defense on Apple Computers at this time.

Jun 2, 2017 11:42 AM in response to JimmyCMPIT

Anti-virus and malware scanners do different things. I've had Sophos running on my old machine for around a year and a half or more and not had many false-positives at all. However, both Malwarebytes and Sophos apparently don't run well on the same system together, so I'm going to have to choose one and as malware is more deadly these days (and more proliferate on macOS) I'm inclined to make a switch.


Apparently Apple does "recommend" it, but I've not found any official documentation online supporting this, so it could just be verbal fro their stores? I know that Apple do use a 3rd party de-fragmenter, but I use SSD now.


If I was worried about false positives I'd stay away from Little Snitch, which is one BIG easily-triggered pop-up **** of an app, but understand that a firewall other than Apple's official offering would be a smart move.

Jun 2, 2017 12:08 PM in response to Hamper

Actually even the firewall is unnecessary if you are behind a router. Also, Mac's own built-in security features protect your Mac very well. I wasn't aware that Apple recommend Sophos. It would be nice to see some documentation, or did a rep in an Apple Store suggest that? I can see them suggesting it, if you were also running Windows. Of course, if you just look in the AppStore, they're selling all sorts of stuff that wouldn't be any good for your Mac.

Jun 2, 2017 4:49 PM in response to ishrugged

Sophos has active "protection" whereas MBAM is only an on-demand scanner (at least for now). Are they detecting each other's signatures?

MBAM only finds and removes Adware. It does no active scanning, which is not needed on a Mac. If you let yourself be tricked into installing Adware, MBAM usually can remove it. Unless Sophos installs Adware (certainly possible from my point of view), then MBAM would likely detect it.

As far as I know, there is no AV package that will detect and prevent you from installing Adware, though I know some Adware is detected and removed by Protect (or some other part of the OS).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Time Machine protects from ransomware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.