News:

Buffalo provides Data Recovery services. Read about it here.

Main Menu

User rights

Started by AIffland, January 20, 2010, 06:36:40 AM

Previous topic - Next topic

AIffland

   

Hi,

 

is it true that Buffalo NAS (TS-RHTGL/R5 F/W 1.33, AD integrated) checks the user rights from bottom (read only) to the top (read/write)?

 

If so, why?

Normally i have a group with all users that are allowed to access (read) certain files. Then i define the group with those user that have more rights, but i don't have to delete them from the first group.

With the above NAS, i have to define a new group with all those user that should not have write access. This differs from windows behaviour.

 

Could you please confirm and comment.

 

Best regards,

 

Arnd


AIffland

   

No comments on this?


Colin137

The Windows platforms that you're used to are using what's called "least restrictive" permissions. The Linux-based Buffalo NAS devices use "most restrictive" permissions. I'm not about to start an argument about which one's more secure, so I'll just leave it at that.

 

"Least restrictive" vs. "most restrictive" permissions is an old debate going back a while, and there's not really a consensus on what's better.


AIffland

   

Thanks.

 

So the mix of Windows (AD integration) and Linux is the problem?

It's just, when i have an option for AD integration, i just suspect that the user groups will work the same as on the base (windows) system. For this, it don't matter which system is more secure or better. But when i use windows user groups on a NAS that is working complete different regarding user rights, i have a big problem with my group definitions.


Browser ID: smf (is_webkit)
Templates: 4: index (default), Display (default), GenericControls (default), GenericControls (default).
Sub templates: 6: init, html_above, body_above, main, body_below, html_below.
Language files: 5: index+Modifications.english (default), Post.english (default), Editor.english (default), Drafts.english (default), StopForumSpam.english (default).
Style sheets: 4: index.css, attachments.css, jquery.sceditor.css, responsive.css.
Hooks called: 164 (show)
Files included: 35 - 1354KB. (show)
Memory used: 1003KB.
Tokens: post-login.
Queries used: 16.

[Show Queries]