ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    To Password Protect a network folder or not

    Scheduled Pinned Locked Moved IT Discussion
    43 Posts 8 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403
      last edited by

      So this question just came up, and it was "Is there a way to password protect a networked folder and its contents, while still having it be useful?"

      We could encrypt the folder, but wouldn't this have to be un-encrypted every time a user wants to access the contents?

      I know windows supports encrypting files, but this seems extremely painful, especially for a network based folder.

      My recommendation is to make a share out of the folder (or sub-folder), and control it with standard security permissions.

      Is there any better solution you guys have seen?

      scottalanmillerS 3 Replies Last reply Reply Quote 2
      • scottalanmillerS
        scottalanmiller @DustinB3403
        last edited by

        @DustinB3403 said in To Password Protect a network folder or not:

        We could encrypt the folder, but wouldn't this have to be un-encrypted every time a user wants to access the contents?

        Correct.

        1 Reply Last reply Reply Quote 1
        • scottalanmillerS
          scottalanmiller @DustinB3403
          last edited by

          @DustinB3403 said in To Password Protect a network folder or not:

          I know windows supports encrypting files, but this seems extremely painful, especially for a network based folder.

          And it defeats the purpose of your NTFS security. What does the extra password accomplish?

          DustinB3403D 1 Reply Last reply Reply Quote 3
          • T
            tiagom
            last edited by

            I had this come up previously. I secured it with standard folder permissions. The user logging into their computer is the "password protection".

            scottalanmillerS 1 Reply Last reply Reply Quote 3
            • T
              tiagom
              last edited by

              For some reason users love to try and put passwords on everything.. If only they could remember them...

              DustinB3403D 1 Reply Last reply Reply Quote 3
              • DustinB3403D
                DustinB3403 @tiagom
                last edited by

                @tiagom said in To Password Protect a network folder or not:

                For some reason users love to try and put passwords on everything.. If only they could remember them...

                Yes, this is a big issue.

                1 Reply Last reply Reply Quote 2
                • scottalanmillerS
                  scottalanmiller @DustinB3403
                  last edited by

                  @DustinB3403 said in To Password Protect a network folder or not:

                  My recommendation is to make a share out of the folder (or sub-folder), and control it with standard security permissions.

                  Is there any better solution you guys have seen?

                  As it is, shares have NTFS (at least if using Windows) and SMB security. That's two whole levels, one that always applies and then extra lock down when shared. You can encrypt below that level if you need encryption, this integrates the encryption into the existing security.

                  Having a second password for a file or folder will not actually increase security, just make people start looking to work around the system by making file copies or whatever. It doesn't increase security technically in any real way, but it does increase overhead which is the same as social engineering your staff to be less secure (like forcing pointless password requirements that causes them to write passwords down.)

                  1 Reply Last reply Reply Quote 2
                  • scottalanmillerS
                    scottalanmiller @tiagom
                    last edited by

                    @tiagom said in To Password Protect a network folder or not:

                    I had this come up previously. I secured it with standard folder permissions. The user logging into their computer is the "password protection".

                    Yup, this is important. Refer to it as the "second, useless password." Anytime it comes up, state that it is already password protected and if it needs to be encrypted, that's fine, but encryption is always a protection against physical theft, never against the users who will be turning it off every time they access the file.

                    1 Reply Last reply Reply Quote 3
                    • DustinB3403D
                      DustinB3403 @scottalanmiller
                      last edited by

                      @scottalanmiller said in To Password Protect a network folder or not:

                      @DustinB3403 said in To Password Protect a network folder or not:

                      I know windows supports encrypting files, but this seems extremely painful, especially for a network based folder.

                      And it defeats the purpose of your NTFS security. What does the extra password accomplish?

                      That was my mindset as well, why should we encrypt it when we could use simple share and security policies to control access to the content.

                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @DustinB3403
                        last edited by

                        @DustinB3403 said in To Password Protect a network folder or not:

                        @scottalanmiller said in To Password Protect a network folder or not:

                        @DustinB3403 said in To Password Protect a network folder or not:

                        I know windows supports encrypting files, but this seems extremely painful, especially for a network based folder.

                        And it defeats the purpose of your NTFS security. What does the extra password accomplish?

                        That was my mindset as well, why should we encrypt it when we could use simple share and security policies to control access to the content.

                        Having the person requesting this state the benefit might be important. Ask them "Given that the resource is already controlled by a password and restricted to the user level for access and further limited on the network and that passwords should never be shared, ever, what is the GOAL, what is the "intended benefit" that someone perceives from this action?"

                        1 Reply Last reply Reply Quote 1
                        • T
                          tiagom
                          last edited by

                          I actually asked where did you get this idea to password protect a folder. The times that i encounter this its always from non-technical end users who are used to password protecting office documents.

                          1 Reply Last reply Reply Quote 1
                          • C
                            Carnival Boy
                            last edited by

                            @scottalanmiller said in To Password Protect a network folder or not:

                            Having a second password for a file or folder will not actually increase security,

                            I agree on folders. Not sure on files. Using NTFS only, is it possible to set permissions to allow access to only a specific user and no-one else? Ie can you restrict the domain admin or the file server's local admin account from access? And if you could, could you still back the file up? I wouldn't want a file on my file server that I, as domain admin, was restricted to. I'm not sure it would work?

                            Some users will password protect Office files from within Office and I don't have a particular problem with that. I can still access the file to back it up, restore it and change NTFS permissions, but I can't open the file in Office. That suits me. I wouldn't encourage it, as if the user leaves or forgets the password, I can't help. It adds more risk to the company than it solves.

                            coliverC scottalanmillerS 5 Replies Last reply Reply Quote 1
                            • coliverC
                              coliver @Carnival Boy
                              last edited by

                              @Carnival-Boy said in To Password Protect a network folder or not:

                              @scottalanmiller said in To Password Protect a network folder or not:

                              Having a second password for a file or folder will not actually increase security,

                              I agree on folders. Not sure on files. Using NTFS only, is it possible to set permissions to allow access to only a specific user and no-one else? Ie can you restrict the domain admin or the file server's local admin account from access? And if you could, could you still back the file up? I wouldn't want a file on my file server that I, as domain admin, was restricted to. I'm not sure it would work?

                              Some users will password protect Office files from within Office and I don't have a particular problem with that. I can still access the file to back it up, restore it and change NTFS permissions, but I can't open the file in Office. That suits me. I wouldn't encourage it, as if the user leaves or forgets the password, I can't help. It adds more risk to the company than it solves.

                              You can easily have a set of files your domain admin or file server admins don't have access to but your backup service account does, assuming you are doing file level backups,

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @Carnival Boy
                                last edited by

                                @Carnival-Boy said in To Password Protect a network folder or not:

                                I agree on folders. Not sure on files. Using NTFS only, is it possible to set permissions to allow access to only a specific user and no-one else?

                                Yes, of course. You can set any permission granularity on any file. Per user, per group, read, write, modify. NTFS ACLs always provide this.

                                1 Reply Last reply Reply Quote 2
                                • scottalanmillerS
                                  scottalanmiller @Carnival Boy
                                  last edited by

                                  @Carnival-Boy said in To Password Protect a network folder or not:

                                  Ie can you restrict the domain admin or the file server's local admin account from access?

                                  No, that you cannot do. The domain admin always has access. It is true that encrypting a file could keep the admin from accessing a file, but that also means a fundamental failing of the overall system. The admin can always access that file in another way if that file gets accessed, and you have to trust your admins or you are already compromised. So while that's technically a reason, I don't see it as a valid one. Your admin can just grab a copy of that file if they want when it is accessed defeating the purpose. Plus the shared password system is totally non-secure. So not really useful in securing anything either, if it comes to actually trying to secure it.

                                  C 1 Reply Last reply Reply Quote 2
                                  • scottalanmillerS
                                    scottalanmiller @Carnival Boy
                                    last edited by

                                    @Carnival-Boy said in To Password Protect a network folder or not:

                                    And if you could, could you still back the file up? I wouldn't want a file on my file server that I, as domain admin, was restricted to.

                                    Yes, that works fine, because in no way are you (as the admin) restricted from accessing the file. You can copy it, back it up, move it, etc. just like any other file. Remember that "encrypted" isn't something special here, think of it like a Word Doc being accessed by a computer that does not have Word installed. An encrypted file is just a file for which you do not have the application that opens it, nothing more. A computer copying or backing up any file will not know what is in that file, it just copies the whole thing.

                                    1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @Carnival Boy
                                      last edited by

                                      @Carnival-Boy said in To Password Protect a network folder or not:

                                      Some users will password protect Office files from within Office and I don't have a particular problem with that. I can still access the file to back it up, restore it and change NTFS permissions, but I can't open the file in Office. That suits me. I wouldn't encourage it, as if the user leaves or forgets the password, I can't help. It adds more risk to the company than it solves.

                                      That is exactly what they are looking to do here. Maybe not Office files, but exact same concept.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @coliver
                                        last edited by

                                        @coliver said in To Password Protect a network folder or not:

                                        You can easily have a set of files your domain admin or file server admins don't have access to but your backup service account does, assuming you are doing file level backups,

                                        Actually you can't. You can have a second admin who only has access to them, but some human admin, at the end of the day, always has access.

                                        coliverC 1 Reply Last reply Reply Quote 1
                                        • coliverC
                                          coliver @scottalanmiller
                                          last edited by

                                          @scottalanmiller said in To Password Protect a network folder or not:

                                          @coliver said in To Password Protect a network folder or not:

                                          You can easily have a set of files your domain admin or file server admins don't have access to but your backup service account does, assuming you are doing file level backups,

                                          Actually you can't. You can have a second admin who only has access to them, but some human admin, at the end of the day, always has access.

                                          You can gain access, true.

                                          1 Reply Last reply Reply Quote 0
                                          • wirestyle22W
                                            wirestyle22
                                            last edited by

                                            tl;dr there is no reason to do this

                                            1 Reply Last reply Reply Quote 2
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post