security concerns from a new user
Posted: Fri Jan 08, 2010 3:57 am
Dear AMAHI Team,
first of all: Congratulation to this simple to install home server system!
But to be frank I am concerned if Amahi is a safe and secure system?
There have been some issues today that cut my trust a bit.
Issue 1:
I installed AjaXplorer as user A. When I logged into my HDA as user B AjaXplorer gave me access to all files even to those I had no permission to (e.g. files of user A).
Issue 2:
On my HDA machine each user can browse through all linux directories and system files. Shouldn't this be possible only for the root?
I know AMAHI stuff will not be interested in my files and probably all that are worries of of a newbie who is not very experienced in Linux.
Maybe you can give me back my confidence
And a question: Do I have to modify the firewall of my HDA? I noticed that it is deactivated.
Thanks a lot.
Alf