• System Protection (Restore Points)

    From Brian Gregory@void-invalid-dead-dontuse@email.invalid to alt.comp.os.windows-11 on Fri Jul 31 01:08:29 2026
    From Newsgroup: alt.comp.os.windows-11

    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own???
    --
    Brian Gregory (in England).

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From sticks@wolverine01@charter.net to alt.comp.os.windows-11 on Thu Jul 30 19:18:19 2026
    From Newsgroup: alt.comp.os.windows-11

    On 7/30/2026 7:08 PM, Brian Gregory wrote:
    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own

    googles answer:

    The culprit is a newly introduced feature in Windows 11 called
    "Point-in-time restore", which actively overrides and resets your
    classic System Protection slider.

    Why This Is Happening In your specific build of Windows 11 25H2,
    Microsoft bundles a modern Point-in-time restore mechanism into the
    Settings app. Even though it looks different from the legacy Control
    Panel interface, both features share the exact same underlying VSS
    (Volume Shadow Copy) storage pool on your C: drive.The new
    "Point-in-time restore" feature has its own maximum storage slider,
    which defaults to roughly 2% to 3%. Windows periodically runs a
    background maintenance task that forces the VSS pool to match the modern feature's configuration. Every time this task triggers, it silently
    overwrites your 10% setting back down to its own ~2% default,
    unfortunately purging your older restore points along with it.

    How to Fix It Permanentely. To keep your storage pool at 10%, you have
    to change the setting through the modern interface so Windows stops
    fighting itself.Open the Settings app (Win + I).Navigate to System > Recovery.Look for the Point-in-time restore section and select View or
    edit (or click into its configuration menu).Adjust the Disk usage slider inside this menu to your preferred capacity.Once you save the change
    here, the system will lock that value into the shared pool, and your
    classic System Protection slider will finally stay where you want it.
    --
    Science DoesnrCOt Support Darwin. Scientists Do

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From VanguardLH@V@nguard.LH to alt.comp.os.windows-11 on Thu Jul 30 23:00:07 2026
    From Newsgroup: alt.comp.os.windows-11

    Brian Gregory <void-invalid-dead-dontuse@email.invalid> wrote:

    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own???

    Unclear is if what you state is about the reserve space versus the used
    space reserved for SR points. When looking at SR configurations (a
    per-drive setting), are you looking at Current Usage, or at Max Usage?

    You also don't state how much free space there is on the drive where SR
    is enabled. SR is a per-drive setting. Some drives can have it
    enabled, so have it disabled, and the amount for Max Usage (and Current
    Usage) can be different for each drive. Windows requires a minimum free
    space on the system drive for its own use outside of SR points. You
    can't be trying to use all available free space on a drive to dedicate
    to SR points storage.

    SR points are automatically discarded when they reach 60 days of age.
    No matter how much you set for reserve space, SR points will expire
    based on age, not based on available free space within the SR storage
    quota. SR points always expired, but now they expire sooner.

    https://www.windowslatest.com/2025/06/21/windows-11-24h2-system-restore-points-now-expire-after-60-days-microsoft-confirms/

    The SR backups used to expire when there wasn't sufficient remaining
    capacity in the specified reserve storage for SR points. In Windows 11,
    that changed to 60 days for expiration. I'm not sure this Win11 change
    is reflected into earlier versions of Windows.

    I don't bother with SR points, and instead use a 3rd-party imaging
    backup program to let me restore the EXACT same prior state of a drive.
    SR does not restore back to a prior state of a drive. It restores only
    files, and only the system files. It will not eradicate malware in
    other (non-system/app) files. It will not undo any corruption of other
    files. It's to get Windows working again, but a restore does not
    guarantee the system fileset is in full sync at some update level.

    System Restore should NOT be viewed as a backup scheme. It is merely an [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is
    required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Brian Gregory@void-invalid-dead-dontuse@email.invalid to alt.comp.os.windows-11 on Fri Jul 31 14:00:33 2026
    From Newsgroup: alt.comp.os.windows-11

    On 31/07/2026 01:18, sticks wrote:
    On 7/30/2026 7:08 PM, Brian Gregory wrote:
    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System
    Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own

    googles answer:

    The culprit is a newly introduced feature in Windows 11 called "Point- in-time restore", which actively overrides and resets your classic
    System Protection slider.

    Why This Is Happening In your specific build of Windows 11 25H2,
    Microsoft bundles a modern Point-in-time restore mechanism into the
    Settings app. Even though it looks different from the legacy Control
    Panel interface, both features share the exact same underlying VSS
    (Volume Shadow Copy) storage pool on your C: drive.The new "Point-in-
    time restore" feature has its own maximum storage slider, which defaults
    to roughly 2% to 3%. Windows periodically runs a background maintenance
    task that forces the VSS pool to match the modern feature's
    configuration. Every time this task triggers, it silently overwrites
    your 10% setting back down to its own ~2% default, unfortunately purging your older restore points along with it.

    How to Fix It Permanentely.-a To keep your storage pool at 10%, you have
    to change the setting through the modern interface so Windows stops
    fighting itself.Open the Settings app (Win + I).Navigate to System > Recovery.Look for the Point-in-time restore section and select View or
    edit (or click into its configuration menu).Adjust the Disk usage slider inside this menu to your preferred capacity.Once you save the change
    here, the system will lock that value into the shared pool, and your
    classic System Protection slider will finally stay where you want it.



    Thank you.
    --
    Brian Gregory (in England).
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From sticks@wolverine01@charter.net to alt.comp.os.windows-11 on Fri Jul 31 08:30:40 2026
    From Newsgroup: alt.comp.os.windows-11

    On 7/31/2026 8:00 AM, Brian Gregory wrote:
    On 31/07/2026 01:18, sticks wrote:

    ---snip---

    How to Fix It Permanentely.-a To keep your storage pool at 10%, you
    have to change the setting through the modern interface so Windows
    stops fighting itself.Open the Settings app (Win + I).Navigate to
    System > Recovery.Look for the Point-in-time restore section and
    select View or edit (or click into its configuration menu).Adjust the
    Disk usage slider inside this menu to your preferred capacity.Once you
    save the change here, the system will lock that value into the shared
    pool, and your classic System Protection slider will finally stay
    where you want it.



    Thank you.

    Yep, Mine was down at 2% also. I raised mine up a bit too as disk space
    is available for me.
    --
    Science DoesnrCOt Support Darwin. Scientists Do

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From s|b@me@privacy.invalid to alt.comp.os.windows-11 on Fri Jul 31 16:26:21 2026
    From Newsgroup: alt.comp.os.windows-11

    On Fri, 31 Jul 2026 01:08:29 +0100, Brian Gregory wrote:

    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own???

    I haven't, I'm sorry. But just a suggestion since my experience with
    System Restore is overall negative; it leaves stuff behind when it
    "restores".

    Why don't you turn it off and create your own images? I'm using Macrium
    Reflect Free (the last free version 8.*), but there's also Hasleo Backup
    Suite Free:

    <https://www.easyuefi.com/backup-software/backup-suite-free.html>

    It lets you create backup images and when you restore an image
    everything will be as it was when you made the image. No crap left
    behind.
    --
    s|b
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Mark Lloyd@not.email@all.invalid to alt.comp.os.windows-11 on Fri Jul 31 16:55:19 2026
    From Newsgroup: alt.comp.os.windows-11

    On Thu, 30 Jul 2026 23:00:07 -0500, VanguardLH wrote:

    [snip[

    System Restore should NOT be viewed as a backup scheme. It is merely an [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.

    Scheduled backup may be a good idea, but it requires the backup device to
    be always connected to the PC. Removing the device except during backup
    would be better. For one thing, a virus can't infect a file on a
    disconnected device.
    --
    Mark Lloyd
    http://notstupid.us/

    Obey Psalms 137:9!
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Paul@nospam@needed.invalid to alt.comp.os.windows-11 on Fri Jul 31 16:23:19 2026
    From Newsgroup: alt.comp.os.windows-11

    On Fri, 7/31/2026 12:55 PM, Mark Lloyd wrote:
    On Thu, 30 Jul 2026 23:00:07 -0500, VanguardLH wrote:

    [snip[

    System Restore should NOT be viewed as a backup scheme. It is merely an
    [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is
    required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups
    yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.

    Scheduled backup may be a good idea, but it requires the backup device to
    be always connected to the PC. Removing the device except during backup would be better. For one thing, a virus can't infect a file on a disconnected device.


    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From VanguardLH@V@nguard.LH to alt.comp.os.windows-11 on Fri Jul 31 16:04:41 2026
    From Newsgroup: alt.comp.os.windows-11

    Mark Lloyd <not.email@all.invalid> wrote:

    On Thu, 30 Jul 2026 23:00:07 -0500, VanguardLH wrote:

    [snip[

    System Restore should NOT be viewed as a backup scheme. It is merely an
    [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is
    required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups
    yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.

    Scheduled backup may be a good idea, but it requires the backup device to
    be always connected to the PC. Removing the device except during backup would be better. For one thing, a virus can't infect a file on a disconnected device.

    I have 2 copies of backups: one on an always-attached USB HDD, and
    another on a USB HDD that is attached only when I run Syncback to sync
    the backups on the other USB drive to this one.

    However, the moment you connect an otherwise detached USB drive is the
    moment any malware can attack those "offsite" backup files, like
    ransomware renaming the backup files, encrypting them (even if already encrypted by the backup software), deleting them, etc. You think you're
    safe until the moment you plug in the otherwise disconnect drive.

    I use Macrium Reflect. I has a Guardian feature that blocks all access
    to the backup files. Only Reflect can access the backup files. Malware
    cannot rename, delete, or encrypt those files. In fact, I've got caught
    by Guardian when I tried to copy some backup files elsewhere. I had to
    disable Guardian, copy, and reenable Guardian.

    I did find a very small window of opportunity for malware to get around Guardian, like the UEFI code that Windows will run on startup.
    Microsoft added the UEFI rootkit mostly for software inventorying
    program where employers can monitor what its employees are putting on
    the company's workstations. I can supply my canned response on how the
    UEFI rootkit works. I've never been afflicated with it on any of my
    personal hosts, because no company IT admin touches my home computers,
    and I don't use sysprep images from any company (I do fresh installs).
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Mark Lloyd@not.email@all.invalid to alt.comp.os.windows-11 on Sat Aug 1 16:33:20 2026
    From Newsgroup: alt.comp.os.windows-11

    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snap]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    2. The drive would need to be set up so your backup software can find it.

    3. There's a possibility of backing up an infected system. There's less
    chance of destroying a good backup with a bad one if you use TWO backup devices and alternate between then.

    4. What shuts down the NAS after doing backup?
    --
    Mark Lloyd
    http://notstupid.us/

    "Never build a dungeon you wouldn't be happy to spend the night in
    yourself. The world would be a happier place if more people remembered
    that." - Terry Pratchett
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Frank Slootweg@this@ddress.is.invalid to alt.comp.os.windows-11 on Sat Aug 1 19:59:26 2026
    From Newsgroup: alt.comp.os.windows-11

    Mark Lloyd <not.email@all.invalid> wrote:
    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snap]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    The NAS, at least mine (Synology), doesn't need to be woken up before
    use. Just the first write (or read or whatever) will wake it up.

    2. The drive would need to be set up so your backup software can find it.

    A NAS is always set up (it's on your LAN) and accessible by its share
    name, \\<whatever>\<rest_of_path>.

    3. There's a possibility of backing up an infected system. There's less chance of destroying a good backup with a bad one if you use TWO backup devices and alternate between then.

    With image backup, you can have multiple copies on a single device/
    NAS. Of course that's no protection against device failure, but it is protection against the scenario you mention. The image backups are just
    big files. That one of the images contains an infected system doesn't
    make the image/file dangerous, just when you *restore* such an image,
    the excrements hit the rotating device.

    4. What shuts down the NAS after doing backup?

    On my just not accessing it makes it go to sleep after a settable
    timeout. Sleep not shutdown.I guess one could make it shutdown, but why?
    See VanguardLH's comments on Macrium's Guardian feature, with prevents
    any access - i.e. also by a virus - to Macrium images.

    Having said all that, *I* make *image* backup to alternating (on-site/ off-site) removable USB HDDs and different levels of *file level* backup
    to USB memory-stick, NAS, 'the cloud' (Google Drive) and these removable
    USB HDDs at different intervals (twice-daily, daily, weekly,
    three-monthly). This way, I always have a disaster recovery backup
    offsite and a differential backup of the most important stuff in the
    cloud, so I'm protected against things like fire, theft, etc..
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Paul@nospam@needed.invalid to alt.comp.os.windows-11 on Sat Aug 1 16:33:08 2026
    From Newsgroup: alt.comp.os.windows-11

    On Sat, 8/1/2026 12:33 PM, Mark Lloyd wrote:
    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snap]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    2. The drive would need to be set up so your backup software can find it.

    3. There's a possibility of backing up an infected system. There's less chance of destroying a good backup with a bad one if you use TWO backup devices and alternate between then.

    4. What shuts down the NAS after doing backup?


    There are obviously details to be worked there.

    The NAS needs an RTC (Real Time Clock), which is NTP
    synced to something.

    You would check the backup software, to see if it has
    a "Post-backup Script" you can code up. This would
    include a command to the NAS, to go back to sleep.
    The NAS should, at a minimum, spin down the drive when
    it is not in usage.

    You would not use Wake On LAN for the wakeup process,
    because some malware could sniff around for equipment
    to wake up.

    Such a scheme still has lots of exploit possibilities,
    and all we've done so far, is avoid leaving the drive
    running all the time. You might still need the
    Image Guardian feature or some other sort of Rube Goldberg
    scheme, to improve the protection against ransomware
    alteration.

    Macrium has the ability, to boot into its own WinRE.wim ,
    but since that is stored on the C: drive, I expect something
    can still get into that file and alter it.

    And a lot of these ideas, assume you're not using the
    computer at the time the backup is scheduled to run.

    All I can tell you, is things like Ransomware are extremely
    well designed, and when they hit their trip point (they
    can lay in wait for as long as a month), they wipe out
    your entire room. Then can worm into the other machines,
    if they haven't done that already. Altering or damaging
    your backup collection, is all part of their checklist.

    The people in the most danger, are those who own their
    own domain and chose to include their real email address
    in the GoDaddy registration. If you buy a domain, the
    registration should be "cloaked", so you will not
    start receiving phishing email to that address.

    Paul
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Paul@nospam@needed.invalid to alt.comp.os.windows-11 on Sat Aug 1 16:56:01 2026
    From Newsgroup: alt.comp.os.windows-11

    On Sat, 8/1/2026 3:59 PM, Frank Slootweg wrote:

    Having said all that, *I* make *image* backup to alternating (on-site/ off-site) removable USB HDDs and different levels of *file level* backup
    to USB memory-stick, NAS, 'the cloud' (Google Drive) and these removable
    USB HDDs at different intervals (twice-daily, daily, weekly,
    three-monthly). This way, I always have a disaster recovery backup
    offsite and a differential backup of the most important stuff in the
    cloud, so I'm protected against things like fire, theft, etc..


    I might boot a Macrium CD and start my backup. The
    hard drive used for the backup, is added to the setup
    just before the offline backup. This makes the
    scheme purely manual.

    Doing it that way, doesn't solve all problems. It's
    just a basic way of trying to avoid the easy problems.

    The ransomware people are very good at what they do.
    Any theoretical attack you can think of, their "kit"
    already has code for that. There is a cottage industry
    in those kits, so not all the Black Hats have to be
    geniuses. They can buy the necessary materials from others.

    If you have your own web domain, like a registration
    with GoDaddy, don't forget to "cloak" your email address
    so the email address is not listed. This will reduce the
    amount of phishing email you might receive. The only case
    of Ransomware I've run into, is one USENETTER had a
    GoDaddy domain, a phishing email was sent to him
    (and likely thousands of others) and... he double
    clicked the attachment. And after that, his computer
    room was wiped out.

    Backups aren't as attractive as they once were, as
    the price of HDD has gone up since January. You would
    really want to pay for the backup software that features
    Incremental backups, just to reduce your storage costs.

    Paul
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From VanguardLH@V@nguard.LH to alt.comp.os.windows-11 on Sat Aug 1 19:32:09 2026
    From Newsgroup: alt.comp.os.windows-11

    Paul <nospam@needed.invalid> wrote:

    Mark Lloyd wrote:

    VanguardLH wrote:

    System Restore should NOT be viewed as a backup scheme. It is
    merely an [attempt at a] recovery scheme. It might work, but not
    fix other problems. It might not work (the typical result). It
    wastes disk space. If you want to completely heal your drive, save
    image backups. The image backups should be scheduled. Anytime user
    interventions is required means the image backups are often
    missing, or so long ago that a restore results in severe loss of
    data or apps. Don't do the backups yourself. Schedule them. The
    granularity of those backups depends on how much you can afford to
    lose, and how much storage space you have for the image files.

    Scheduled backup may be a good idea, but it requires the backup
    device to be always connected to the PC. Removing the device except
    during backup would be better. For one thing, a virus can't infect a
    file on a disconnected device.

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Before I had Reflect with its Guardian feature (in its payware version)
    to protect its backup files against malware, I used to use the pre- and post-job scripts that a backup job would run. The pre-job script would
    use devcon.exe, a command-line equivalent of Device Manager, to enable
    the backup drive. It then mounted the backup drive. The backup job
    would run which saved the backup files to an internal HDD, and then
    saved a copy to the external HDD. The post-job script would do the
    reverse: unmount the backup drive, and disable the device.

    https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/devcon

    All this was possible only with a backup program where I could specify
    the batch file to run the pre-job script, and a batch file to run the
    post-job script, and a backup program that would let me save the backup
    files in 2 locations (internal and external HDDs). The obvious flaw
    with this scheme is the window of opportunity for malware while the
    external HDD was enabled and mounted. However, this same window of
    opportunity always exists no matter what scheme you use. If you
    disconnect a USB drive to protect the backups, well, they were
    vulnerable before you disconnected the drive, and vulnerable again when
    you later reconnect the drive to restore images or files. If malware is lurking on your computer, while you are creating the backup files, or
    copying them to a removable drive, or later connect the drive then the
    malware can attack. So, I gave up on the notion that a removable drive
    would protect the backup files. They were vulnerable whenever they were accessible, like backing up, copying, or restoring from them.

    The hope is if you get infected that it is when the removable drive is
    offline, and you discover the infection to eradicate it before you
    reconnect the removable drive, or you boot with another OS, like from a
    USB flash drive or CD, that you hope is clean to restore an image onto
    the system drive(s). That is, keep quiescent the working OS to use
    another OS to restore an image atop the working OS.

    While backing up, and while saving a copy of the backup files to NAS or removable drive, you are vulnerable. When accessing the NAS or
    removable drive for restores, you are again vulnerable. Neither method
    is good anti-malware protection, but is some protection providing you
    have the means to guarantee your OS doesn't get infected during backups,
    during saves of the backup files, and later when restoring from the
    backups. The assumption with disconnected external storage is that it
    is safe from infection. Nope, while creating or restoring, you are
    accessing that external storage, and, BANG, is when malware can attack.

    Macrium's Guardian feature is a kernel-mode driver that restricts access
    to the backup files to only its Reflect program. There is still a
    window of vulnerability even with a file stack handler running as a
    driver. There is the load order of drivers that you don't get to
    control (somehow Macrium figured out how to make their driver load
    early, but I don't know that is guaranteed). It is still vulnerable to Microsoft UEFI rootkit unless you disable it in Windows, which I
    checked, but didn't have to neuter the bastard, because it wasn't
    deployed in my setup (mostly because it was my setup, and not from a
    sysprep image used by IT folks), but my computer isn't totally
    physically secure, so some IMF team could break in to install and
    reenable a UEFI rootkit, but they wouldn't bother since they'd also have physical access to my computer's drives.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Mark Lloyd@not.email@all.invalid to alt.comp.os.windows-11 on Sun Aug 2 17:37:14 2026
    From Newsgroup: alt.comp.os.windows-11

    On 1 Aug 2026 19:59:26 GMT, Frank Slootweg wrote:

    Mark Lloyd <not.email@all.invalid> wrote:
    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snip]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    The NAS, at least mine (Synology), doesn't need to be woken up before
    use. Just the first write (or read or whatever) will wake it up.

    2. The drive would need to be set up so your backup software can find
    it.

    A NAS is always set up (it's on your LAN) and accessible by its share
    name, \\<whatever>\<rest_of_path>.

    That's not OFFLINE for safety.

    3. There's a possibility of backing up an infected system. There's less
    chance of destroying a good backup with a bad one if you use TWO backup
    devices and alternate between then.

    With image backup, you can have multiple copies on a single device/
    NAS. Of course that's no protection against device failure, but it is protection against the scenario you mention. The image backups are just
    big files. That one of the images contains an infected system doesn't
    make the image/file dangerous, just when you *restore* such an image,
    the excrements hit the rotating device.

    Having two backups on a single device that is always online doesn't
    prevent some disaster affecting both. I recommend having two INDEPENDENT backup devices that are physically disconnected except while doing the
    backup and NEVER connected at the same time. A backup you can't restore
    isn't a backup.

    There's also the possibility of a failure during backup, destroying the software on your computer AND the backup in progress. That's one reason
    for having a previous backup still available and offline.

    4. What shuts down the NAS after doing backup?

    On my just not accessing it makes it go to sleep after a settable
    timeout. Sleep not shutdown.I guess one could make it shutdown, but why?
    See VanguardLH's comments on Macrium's Guardian feature, with prevents
    any access - i.e. also by a virus - to Macrium images.

    In that case, the drive is always accessible. ANY program on the PC could access it at any time. That is NOT really offline.

    Having said all that, *I* make *image* backup to alternating (on-site/ off-site) removable USB HDDs and different levels of *file level* backup
    to USB memory-stick, NAS, 'the cloud' (Google Drive) and these removable
    USB HDDs at different intervals (twice-daily, daily, weekly,
    three-monthly). This way, I always have a disaster recovery backup
    offsite and a differential backup of the most important stuff in the
    cloud, so I'm protected against things like fire, theft, etc..

    While cloud backup is a good idea, I consider local backup more important. Cloud backup is difficult to restore when your working disk fails
    completely. I have been using computers for more than 35 years and have
    never had a malware problem requiring restore from backup, but I have had things like unintended deletes and drive failures.
    --
    Mark Lloyd
    http://notstupid.us/

    "Nothing could be more anti-Biblical than letting women vote."
    [Editorial, Harper's Magazine, November 1853]
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Mark Lloyd@not.email@all.invalid to alt.comp.os.windows-11 on Sun Aug 2 17:48:07 2026
    From Newsgroup: alt.comp.os.windows-11

    On Sat, 1 Aug 2026 16:56:01 -0400, Paul wrote:

    [snip]

    I might boot a Macrium CD and start my backup. The hard drive used for
    the backup, is added to the setup just before the offline backup. This
    makes the scheme purely manual.

    Doing it that way, doesn't solve all problems. It's just a basic way of trying to avoid the easy problems.

    The ransomware people are very good at what they do.
    Any theoretical attack you can think of, their "kit" already has code
    for that. There is a cottage industry in those kits, so not all the
    Black Hats have to be geniuses. They can buy the necessary materials
    from others.

    They still can't damage a backup on a device that's not connected to
    anything, even if you need a new computer to restore it to.

    If you have your own web domain, like a registration with GoDaddy, don't forget to "cloak" your email address so the email address is not listed.
    This will reduce the amount of phishing email you might receive. The
    only case of Ransomware I've run into, is one USENETTER had a GoDaddy
    domain, a phishing email was sent to him (and likely thousands of
    others) and... he double clicked the attachment. And after that, his
    computer room was wiped out.

    My website has BOTH a mailto: link (although the address is somewhat
    hidden) and a web form. I often get junk messages from the web form. The
    only things I've ever gotten from mailto: have been when I tested it.

    Backups aren't as attractive as they once were, as the price of HDD has
    gone up since January. You would really want to pay for the backup
    software that features Incremental backups, just to reduce your storage costs.

    They're still important. There's protection from accidental deletes, and programs that update themselves when you want the old version.

    Paul
    --
    Mark Lloyd
    http://notstupid.us/

    "Nothing could be more anti-Biblical than letting women vote."
    [Editorial, Harper's Magazine, November 1853]
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Mark Lloyd@not.email@all.invalid to alt.comp.os.windows-11 on Sun Aug 2 17:58:29 2026
    From Newsgroup: alt.comp.os.windows-11

    On Sat, 1 Aug 2026 16:33:08 -0400, Paul wrote:

    [snip]

    There are obviously details to be worked there.

    The NAS needs an RTC (Real Time Clock), which is NTP synced to
    something.

    Yes, although that's still not as safe as having the drive disconnected
    except while doing the backup (or restore).

    You would check the backup software, to see if it has a "Post-backup
    Script" you can code up. This would include a command to the NAS, to go
    back to sleep.
    The NAS should, at a minimum, spin down the drive when it is not in
    usage.

    You would not use Wake On LAN for the wakeup process, because some
    malware could sniff around for equipment to wake up.

    Such a scheme still has lots of exploit possibilities,
    and all we've done so far, is avoid leaving the drive running all the
    time. You might still need the Image Guardian feature or some other sort
    of Rube Goldberg scheme, to improve the protection against ransomware alteration.

    You just need to unplug the drive after doing a backup.

    Macrium has the ability, to boot into its own WinRE.wim , but since that
    is stored on the C: drive, I expect something can still get into that
    file and alter it.

    And a lot of these ideas, assume you're not using the computer at the
    time the backup is scheduled to run.

    All I can tell you, is things like Ransomware are extremely well
    designed, and when they hit their trip point (they can lay in wait for
    as long as a month), they wipe out your entire room. Then can worm into
    the other machines,
    if they haven't done that already. Altering or damaging your backup collection, is all part of their checklist.

    The people in the most danger, are those who own their own domain and
    chose to include their real email address in the GoDaddy registration.
    If you buy a domain, the registration should be "cloaked", so you will
    not start receiving phishing email to that address.

    Why GoDaddy? I use Hover (hover.com), which is better.

    Paul

    Note: I'm not entirely against scheduled backups. They're much better than
    no backups at all.
    --
    Mark Lloyd
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Paul@nospam@needed.invalid to alt.comp.os.windows-11 on Sun Aug 2 19:46:24 2026
    From Newsgroup: alt.comp.os.windows-11

    On Sun, 8/2/2026 1:37 PM, Mark Lloyd wrote:
    On 1 Aug 2026 19:59:26 GMT, Frank Slootweg wrote:

    Mark Lloyd <not.email@all.invalid> wrote:
    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snip]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    The NAS, at least mine (Synology), doesn't need to be woken up before
    use. Just the first write (or read or whatever) will wake it up.

    2. The drive would need to be set up so your backup software can find
    it.

    A NAS is always set up (it's on your LAN) and accessible by its share
    name, \\<whatever>\<rest_of_path>.

    That's not OFFLINE for safety.

    3. There's a possibility of backing up an infected system. There's less
    chance of destroying a good backup with a bad one if you use TWO backup
    devices and alternate between then.

    With image backup, you can have multiple copies on a single device/
    NAS. Of course that's no protection against device failure, but it is
    protection against the scenario you mention. The image backups are just
    big files. That one of the images contains an infected system doesn't
    make the image/file dangerous, just when you *restore* such an image,
    the excrements hit the rotating device.

    Having two backups on a single device that is always online doesn't
    prevent some disaster affecting both. I recommend having two INDEPENDENT backup devices that are physically disconnected except while doing the backup and NEVER connected at the same time. A backup you can't restore isn't a backup.

    There's also the possibility of a failure during backup, destroying the software on your computer AND the backup in progress. That's one reason
    for having a previous backup still available and offline.

    4. What shuts down the NAS after doing backup?

    On my just not accessing it makes it go to sleep after a settable
    timeout. Sleep not shutdown.I guess one could make it shutdown, but why?
    See VanguardLH's comments on Macrium's Guardian feature, with prevents
    any access - i.e. also by a virus - to Macrium images.

    In that case, the drive is always accessible. ANY program on the PC could access it at any time. That is NOT really offline.

    Having said all that, *I* make *image* backup to alternating (on-site/
    off-site) removable USB HDDs and different levels of *file level* backup
    to USB memory-stick, NAS, 'the cloud' (Google Drive) and these removable
    USB HDDs at different intervals (twice-daily, daily, weekly,
    three-monthly). This way, I always have a disaster recovery backup
    offsite and a differential backup of the most important stuff in the
    cloud, so I'm protected against things like fire, theft, etc..

    While cloud backup is a good idea, I consider local backup more important. Cloud backup is difficult to restore when your working disk fails completely. I have been using computers for more than 35 years and have never had a malware problem requiring restore from backup, but I have had things like unintended deletes and drive failures.


    One of the failure modes I had, was "bad RAM" on the X48 system I used to run.

    I was idly running Verify commands on a set of .mrimg and I found a group
    of three of them, which failed to Verify. And the root cause, was bad
    RAM in the disk buffering area the OS uses. After replacing the RAM,
    the Macrium backups made then had good Verify off that machine, until
    the day the chipset blew for good. That's a failure mode that does
    not involve the source or destination disk drive.

    Paul
    --- Synchronet 3.22a-Linux NewsLink 1.2