Communiversity

Afrikan Liberation Institute => Math and Science (STEM) => Topic started by: Ajamu on Jul 05, 2013, 02:02 PM

Title: OS X: How to secure files from other users on external disks-gctid86426
Post by: Ajamu on Jul 05, 2013, 02:02 PM


How to secure files from other users on external disks | MacFixIt - CNET Reviews (http://reviews.cnet.com/8301-13727_7-57590765-263/how-to-secure-files-from-other-users-on-external-disks/)


 While  OS X makes external drives available to all users on the system, you  can change this to ensure your files are only accessible by you.
 
 (http://www.cnet.com/profile/tkessler/)    by Topher Kessler (http://www.cnet.com/profile/tkessler/)
    June 24, 2013 4:39 PM PDT

'""'
    (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset3.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2011%2F12%2F06%2FHardDriveIconX_90x90.png&hash=c456e83199fad01924471c1f61d939a2f2f734f2)

 If you use an external disk drive with OS X, you may notice that when  it is mounted, it becomes available for all users on the system.  Therefore, if you have files you have saved to a USB drive and you  attach it to your system and you switch user accounts, those files will  be viewable within the second account.
 
In addition, if you have network file sharing enabled, the files on  this drive will be accessible to any user who logs in via the network.
 
This behavior may seem a bit concerning, especially for those who  have set up encryption on secondary drives in hopes of preventing others  from viewing their files, but this is normal behavior in OS X, and  essentially means two things:

   (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset3.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim2%2F2013%2F06%2F24%2FPrivateFilesExternalDrive_270x155.png&hash=0f0196bb827f6435d17813f2828fa0749fda3af8)  (http://i.i.com.com/cnwk.1d/i/tim2/2013/06/24/PrivateFilesExternalDrive.png)
An attached and mounted drive and even private contents on it will be viewable in all user accounts.
  (Credit: Screenshot by Topher Kessler/CNET)

'"
On a related note, there has been past concern about encrypted drives being easily remounted (http://reviews.cnet.com/8301-13727_7-57589396-263/insignificant-bug-keeps-encrypted-disks-unlocked-after-ejecting-in-os-x/)  if you tell it to eject but do not detach them from the system;  however, this is ultimately not a security threat. Simply do not use  encryption to protect data from another account on the system, as this  purpose is not its intent. Instead, only use it to prevent a thief or  other third-party who you have not given access to your computer, from  accessing your files.
').'")."n[/list type=decimal]"'

 If set up independently, encryption will not protect your files from  other local users, and permissions may be overcome by using the drive  with another system. Therefore, the way to fully secure the files on  your external drive is to enable both of these features.

 To do this, first enable encryption on the drive by right-clicking it  in the Finder and choosing the Encrypt Drive option. Supply the  password to use when prompted, and then wait for the drive to remount as  an encrypted volume.

   (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset0.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim2%2F2013%2F06%2F24%2FDrivePermissions_270x278.png&hash=1808c5f7ee5bbf2dd88e0fa6829ad1c1aa1f630d)  (http://i.i.com.com/cnwk.1d/i/tim2/2013/06/24/DrivePermissions.png)
Uncheck this box to enable observation of  access permissions on the external drive. Then set specific access  privileges in the list of users and groups.
  (Credit: Screenshot by Topher Kessler/CNET)  

 Next, enable permissions observation on the drive by selecting it and  pressing Command-I to get information on the drive. In the information  window that appears, expand the Sharing section and click the lock to  authenticate. Then uncheck the option to "Ignore Ownership on this  volume."

 With this setting in place, the system will now observe permissions  restrictions on the drive, which you can set to permit or deny access to  specific users (note that this will only work to manage access for  nonadministrator accounts -- admin accounts will always be able to grant  themselves access to files and folders).

 By default, the drive will be owned by the account that formatted it,  so you should see your username listed as the first item in the Sharing  & Permissions list. Next the drive should have a group association  of "staff" (underneath your username) which is the default group for all  local accounts on the system. This allows you to set global permissions  for accounts other than yours.

 Finally, there should be an "everyone" group that encompasses all  other users on the system, such as a guest user account that is not a  member of the "staff" group.

 At this point, you have two possible approaches for the drive. The  first is to set its permissions so only you have access to it, and the  second is to set it up with a subdirectory or two that is only  restricted to your account, so other accounts can do the same and have  their sequestered and private folders.

   (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset0.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim2%2F2013%2F06%2F24%2FExternalDriveSingleUser_270x278.png&hash=e6917348443a716e68d44ffe7b338bd0d01e1849)  (http://i.i.com.com/cnwk.1d/i/tim2/2013/06/24/ExternalDriveSingleUser.png)
To only allow your account access, remove all groups and users except for your account, and set "everyone" to "no access."
  (Credit: Screenshot by Topher Kessler/CNET)  

 Single-user access

To set the drive so only you have access, in the Sharing &  Permissions section of the information window, choose "no access" for  the "staff" group (or simply select and remove this group altogether).  Then set the "everyone" group to likewise have "no access."

 When finished, click the small gear menu and select the option to  apply these settings to all enclosed items (this step is not needed on  an empty drive).

 At this point the entire drive will be a private, detachable folder  for your account. Even though it will show up as a device in other  accounts on the system, if they try to access it then they will be given  a "permission denied" error.

   (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset3.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim2%2F2013%2F06%2F24%2FExternalDriveMultiUser_270x278.png&hash=22478a2f2fe9f6905cd1d3938b34cab35da6ad50)  (http://i.i.com.com/cnwk.1d/i/tim2/2013/06/24/ExternalDriveMultiUser.png)
To allow multiple users to read the drive, set  the "staff" permissions accordingly. If you set it to "Read Only" (so  the top level of the drive cannot be modified) then be sure to put a  folder on the drive, and set its permissions so each user can read it.  Additionally, be sure to set "everyone" to have no access.
  (Credit: Screenshot by Topher Kessler/CNET)

Multiuser access

To set the drive up so other users have access, leave the drive's  permissions as their default so the "staff" group is intact and has full  read and write permissions. Then open the drive in the Finder and  create a folder on it to store your files. Now get information on this  folder and set it so only your account is in the Sharing &  Permissions list, with "read & write" access, and with all others  set to "no access."

 From here, your account will be able to view the files in this folder, but other accounts will not.

 As an additional security measure, you can set up a similar folder  for each account on the system, and when finished get information on the  drive itself and set the "staff" group to "read only" permissions (do  not use the gear menu's option to apply permissions to enclosed items).  With this setup, when another user opens the drive, they will only be  able to drag items to their specific folder, and neither to another  user's folder nor to the top level of the drive.

 Regardless of the approach you use, at this point you will have a  drive that has secured resources from other users, and one that is also  encrypted and thereby protected from someone attempting to override the  permissions settings by attaching it to another computer.