Don't trust your Groove spaces

by Volker Weber

broken.gif

You can hide a tool in Groove Workspace but you can't protect the data. You are led to believe the data is protected but in fact it isn't.

If you share a Groove space with a number of people, you can assign roles to them. They can be either manager, participant or guest. You can now define which permissions those roles have, both at the space or the individual tool level.

Now let's assume you have one tool that contains data, which only managers are supposed to see, and you assign read permission only to managers. Participants and guests can see this tool tab but not the data in it. Everything is fine so far, although I would prefer to hide the tool completely.

Now, here is the problem: If a participant duplicates the space he will automatically be manager of the duplicate and see all the data in the managers only tool. How bad is that?

Summary: If you put data in a Groove space, then every member can see it. Roles do not protect the data. In Groove's diction, this is not software problem, but a perception problem.

Comments

1) This issue was blown way out of proportion
2) http://www.groove.net/support/technotes/detail.gtml?docid=F3033C9F-FDC6-419C-BF6C-0DABA57A6364

Bubba, even if you are in the shrimp business, there is no need to hide. We do record IP addresses (and trace them). :-)

Post a comment











Shall I remember this for you?




Use your full name and a working email address. Unless you want your comment to be removed. No kidding.



Ceci n'est pas un blog

vowe.net is a personal website published by Volker Weber a.k.a. vowe. I am an author, consultant and systems architect based in Darmstadt, Germany.

rss Click here to subscribe

Hello

About me
Contact
Publications
Certificates
Frequently asked questions
Join the network

Twitter Updates

More >

Poll

Which Smartphone do you want?

Getting poll results. Please wait...

Local time is 22:31

visitors.gif
133 visitors online

News

Other sources of news, imported into my own format to make them more accessible:

Heise Online
Schlagzeilen
Weather

Archives

As most of my articles roll off the front page rather quickly, I am making an archive of previous posts available here. You can also use the handy search box at the top of the page if you are looking for something particular.

Last 30 days
More archives

Got the T-shirt?

Got the T-shirt?

Systems Architecture

This site runs on an Apache web server on top of the Linux operating system. The content is managed with MovableType which is implemented in Perl. Last but not least the HTML code your browser sees is put together with PHP.

© 1992-2009 Volker Weber.
All Rights Reserved.

Impressum