Don't trust your Groove spaces

by Volker Weber

broken.gif

You can hide a tool in Groove Workspace but you can't protect the data. You are led to believe the data is protected but in fact it isn't.

If you share a Groove space with a number of people, you can assign roles to them. They can be either manager, participant or guest. You can now define which permissions those roles have, both at the space or the individual tool level.

Now let's assume you have one tool that contains data, which only managers are supposed to see, and you assign read permission only to managers. Participants and guests can see this tool tab but not the data in it. Everything is fine so far, although I would prefer to hide the tool completely.

Now, here is the problem: If a participant duplicates the space he will automatically be manager of the duplicate and see all the data in the managers only tool. How bad is that?

Summary: If you put data in a Groove space, then every member can see it. Roles do not protect the data. In Groove's diction, this is not software problem, but a perception problem.

Comments

1) This issue was blown way out of proportion
2) http://www.groove.net/support/technotes/detail.gtml?docid=F3033C9F-FDC6-419C-BF6C-0DABA57A6364

Bubba, even if you are in the shrimp business, there is no need to hide. We do record IP addresses (and trace them). :-)

Post a comment











Shall I remember this for you?




Use your full name and a working email address. Unless you want your comment to be removed. No kidding.



Recent comments

Mathias Ziolo on International OpenOffice market shares at 14:58
Gregory Engels on International OpenOffice market shares at 14:47
Gregory Engels on International OpenOffice market shares at 14:17
Andrew Magerman on International OpenOffice market shares at 11:19
Hans Bornich on Download and install Symphony 3 Beta 2 in 20 easy to follow steps at 10:35
Hynek Kobelka on Leiterin Kommunikation und Presse, ahnungslos at 10:02
Dirk Steins on Do you see it? at 08:01
Arthur Fontaine on Do you see it? at 07:43
patrick picard on Do you see it? at 00:30
Mathias Ziolo on Leiterin Kommunikation und Presse, ahnungslos at 18:21
Thomas Lang on FT.com - A fight over freedom at Apple's core at 17:35
Giulio Campobassi on Download and install Symphony 3 Beta 2 in 20 easy to follow steps at 11:23
Peter Foster on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 19:17
Volker Weber on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 07:38
Peter Foster on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 03:18
Paul Mooney on FT.com - A fight over freedom at Apple's core at 18:12
Todd dal on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 23:03
Frank Paolino on Clothing drive at 22:47
Craig Wiseman on Embrace Life at 22:27
Volker Weber on Clothing drive at 20:40
Carl Tyler on Clothing drive at 20:28
Claude Lehmann on FT.com - A fight over freedom at Apple's core at 19:13
Ragnar Schierholz on FT.com - A fight over freedom at Apple's core at 19:02
Volker Weber on FT.com - A fight over freedom at Apple's core at 12:23
Mathias Ziolo on FT.com - A fight over freedom at Apple's core at 11:15

Ceci n'est pas un blog

vowe.net is a personal website published by Volker Weber a.k.a. vowe. I am an author, consultant and systems architect based in Darmstadt, Germany.

rss Click here to subscribe

Hello

About me
Contact
Publications
Certificates
Frequently asked questions
Join the network

Twitter Updates

More >

Local time is 16:03

visitors.gif
225 visitors online

News

Other sources of news, imported into my own format to make them more accessible:

Schlagzeilen
Weather

Archives

As most of my articles roll off the front page rather quickly, I am making an archive of previous posts available here. You can also use the handy search box at the top of the page if you are looking for something particular.

Last 30 days
More archives

Got the T-shirt?

Got the T-shirt?

Systems Architecture

This site runs on an Apache web server on top of the Linux operating system. The content is managed with MovableType which is implemented in Perl. Last but not least the HTML code your browser sees is put together with PHP.

© 1992-2010 Volker Weber.
All Rights Reserved.

Impressum