Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

islade

macrumors newbie
Original poster
Mar 6, 2014
26
8
Hi,

I've set up two shares on my nMP running Yosemite:
I've shared my 12tb external drive for just myself and I've shared a 'movies' folder for both myself and a 'sharing-only' account for my girlfriend.

When I log in on my MBP as myself, I can access both shares as I should be able to (i have permission to both).

When she logs in as her, she can also access both, even though her account only has access to the 'movies' folder and 'everyone' is denied to the 12tb share. If I add her to the share, there isn't a deny option, so I've just left her out and denied everybody.

What can I do to make sure she can access movies but not the 12tb drive?

I've tried updating all computers involved, removing and recreating share, triple checking sharing permissions on the folders in finder without success.
 
  • Like
Reactions: grahamperrin
This is indeed disturbing. I have compared a directory, a mounted disk image and a mounted thumb drive (HFS+) on Mavericks. Only for the latter are the permissions overridden to read & write for ‘everyone’. That is... good to know. o_O
 
Yeah, and –

a mounted thumb drive (HFS+)

– the problem is not limited to USB or thumb drives.

At its simplest, it's an Apple workflow problem:
  1. connect a drive with an HFS Plus volume
  2. share the volume, and set 'Everyone' to 'No Access'
  3. discover that the access restriction is not enforced.
 
https://www.wilderssecurity.com/threads/386302/ offers additional context but it's not intended to be a comprehensive summary of interactions between me and Apple.

From a follow-up in January 2016: "… we do not see any actual security implications. …". There is some understandable justification for that observation by Apple, and you might slap your forehead when you realise the justification, however we can not assume that all Mac users of file sharing will have that head-slapping moment.

When I next boot pre-release Sierra, I'll look to see whether the GUI has been improved to avoid future incidents.
 
  • Like
Reactions: 997440
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.