![]() |
| Do you know how to secure your files on external disks used with OS X |
When the external disk drive is mounted with OS X, it becomes available for other users too who are currently on the system. When you attach USB drive to the system and switch to your user accounts, all the files of the drive
will now be viewable withing the second account.
More to this, if the network file sharing is enabled, all the files will get accessible to all the other users who logs in via the network even if it is encrypted. This means two things:
01. Encryption of the disk only means securing the content available on the drive from access if it is locked. It will not be able to protect the file from another user on the system. Unlocking it will further make it accessible by other users like a Firewire drive or USB.
02. External drives are by default open to all users. The feature of permissible restrictions is turned off in the OS X as permissions settings are just for one specific operating system installation.
If you set your encryption independently then protection of files from other local users is not possible. So, here you need to enable encryption for the system as a whole instead of one operating system.
For this you need to first enable the encryption on the drive. To do this right click in the Finder and select the Encrypt Drive option. Enter the password required when prompted. After doing this, wait for few seconds so that the drive is remounted as an encrypted volume.
After doing this, you need to enable permissions observation on the drive. Simply select it and then press Command-I to avail the information. Once the information window comes up, you need to expand the Sharing section and then click the lock to authenticate. Next you need to uncheck "Ignore Ownership on this volume" option.
The system is now enabled to permissions restrictions on the drive.
Remember, the drive even now will be owned by that account which formatted it. You can check your username listed on it as the first item in Sharing & Permissions list. Below that you can see group association of "staff" and this will be default group for local accounts on the system. This will allow you in setting up global permissions for other accounts.
After all these, there will be an "everyone" group underneath, which is for all the other users available on the system like guests who is not member of the staff group.
Here you get two approaches. You can set permissions to your access only and the second set up can be with a subdirectory or two that restricts to your account only. Other accounts can also set up the same and have their sequestered and private folders.
Single-user access
Here's how you can set up the external disks drive in such a way that only you have the access. Go to the Sharing & Permissions section on the information window and there select "no access" for "staff" group. You can try selecting and removing this group. Next, set "everyone" group and then select "no access".
After doing all these click on the small gear menu and choose apply these settings to all the enclosed items. This will make the entire drive private. It will show to other accounts but they can't access it.
Multiuser access
Here first leave the permissions of the drive as default so that the "staff" group is intact and get the complete access. Next, open Finder and create a folder there where you can store your files. Now, set it up to only your account in the Sharing & Permissions list and "no access" to others.
In this case your account can view the files but other accounts can't.
Additionally, you can also set up a similar folder for each account and then set up permissions to "read only" for the "staff". With this the other accounts will only be able to drag items to their specific folder only.
How is the solution? Liked it? Do share your own views about it. Also, if there is any other way. Use the below given comment box.





















Hey guys good post
ReplyDeleteWeb Designer in Bangalore