Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

What are “dropboxes”?

dropboxes
0
Posted

What are “dropboxes”?

0

When the ACL on a directory is set to “irl”, this creates what is called a “dropbox”. In theory, users should be able to deposit files in the directory, but not modify them once deposited. In practice, the “not modify them once deposited” part is not enforced by the fileserver; only the OpenAFS client enforces this restriction. Thus, you should not depend on this for security. Also, note that system:anyuser=irl has additional problems: because dropbox semantics are based on pts identities (see question 2.21), the fileserver cannot distinguish between two unauthenticated users. So, not only can a user come back days later and modify the “dropped” file, but any user can modify a file dropped by an unauthenticated user, at any time.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.