|
For a Time Capsule's shared disks I have always used a different password from the main device password since this seems more secure. Am I correct in thinking that for TimeCapsuleSMB the disks HAVE to use the device password and so 'With device password' MUST be selected in AirPort Utility? Perhaps not a huge problem but it does mean that anyone backing up to the Time Capsule and hence needing the password in their keychain can therefore gain full access to the device itself and possibly modify its configuration. Doesn't seem a great idea to me. Or am I misunderstanding something? |
Replies: 2 comments
|
Yes. This is kind of a leftover issue from back when this was just a few bash scripts. I figured nobody would complain much about this, since 99% of people are the main user for their device anyways. The technical reason is because samba reuses the user account logged into the device. The BSD kernel actually doesn't gracefully support the syscall that samba uses to switch users (Samba will straight up crash), so the ONLY user it supports is root. Annoying, I know. I can't really fix it without reverse engineering the kernel Apple uses, and that's a bit beyond the scope of this project. |
|
Understood and thanks for the explanation. It's just my wife and myself using Time Machine that will require the password so no big deal here, but for a less controlled environment probably not ideal. As you said though, these devices will unlikely be used in any 'Enterprise' situation. Again though, great work James. Much appreciated. |
Yes. This is kind of a leftover issue from back when this was just a few bash scripts.
I figured nobody would complain much about this, since 99% of people are the main user for their device anyways.
The technical reason is because samba reuses the user account logged into the device. The BSD kernel actually doesn't gracefully support the syscall that samba uses to switch users (Samba will straight up crash), so the ONLY user it supports is root. Annoying, I know. I can't really fix it without reverse engineering the kernel Apple uses, and that's a bit beyond the scope of this project.