LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-28-2014, 03:10 AM   #1
qlue
Member
 
Registered: Aug 2009
Location: Umzinto, South Africa
Distribution: Crunchbangified Debian 8 (Jessie)
Posts: 747
Blog Entries: 1

Rep: Reputation: 172Reputation: 172
Need NTFS USB 1TB hard drive needs to be read only except under Linux


I use Crunchbang Linux on my own machines exclusively and hence, I format most of my external drives as ext4

However, I regularly transfer files to colleagues via an NTFS formatted 1TB drive. (they all use various versions of Windows)

I need a way to protect this drive from malware and user-error on these Windows machines.

Is there any way to make an NTFS drive read-only by default but writeable on my machine?

Alternatively, is there any alternative to NTFS that won't require installing additional software to everyone else's Windows machines?
 
Old 12-28-2014, 04:28 AM   #2
Doc CPU
Senior Member
 
Registered: Jun 2011
Location: Stuttgart, Germany
Distribution: Mint, Debian, Gentoo, Win 2k/XP
Posts: 1,099

Rep: Reputation: 344Reputation: 344Reputation: 344Reputation: 344
Hi there,

Quote:
Originally Posted by qlue View Post
Is there any way to make an NTFS drive read-only by default but writeable on my machine?
yes, there is. Once the drive is connected to a Windows machine, you can adjust the NTFS access rights so that nobody has write permission any more (except Administrator, maybe). There's the convenient side effect that the Windows boxes won't keep creating that silly "System Volume Information" directory each time the drive is connected.

The Linux NTFS driver doesn't care about NTFS access rights, so you can always write to the drive from Linux.

The downside of this procedure is that your colleagues can't give any files back to you this way.

Quote:
Originally Posted by qlue View Post
Alternatively, is there any alternative to NTFS that won't require installing additional software to everyone else's Windows machines?
Probably not. The only file systems Windows supports natively is the FAT family and NTFS. Anything else, for instance ext2/3, will require an extra driver.

[X] Doc CPU
 
Old 12-28-2014, 07:56 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by Doc CPU View Post
yes, there is. Once the drive is connected to a Windows machine, you can adjust the NTFS access rights so that nobody has write permission any more (except Administrator, maybe).
Here's a convenient script for setting the ro flag by volume label: https://gist.github.com/mmdemirbas/5229315


Quote:
Originally Posted by qlue View Post
I need a way to protect this drive from malware and user-error on these Windows machines.
Then ensuring all users are properly educated about safe browsing / networking habits, logging, auditing and adjusting unwanted behaviour, denying Administrator privileges, making regular backups, filtering network access and deploying a good antivirus solution should be the first measures to take.
Setting a NTFS volumes readonly flag is like combating symptoms and not addressing the real cause(s).
 
Old 12-28-2014, 08:08 AM   #4
qlue
Member
 
Registered: Aug 2009
Location: Umzinto, South Africa
Distribution: Crunchbangified Debian 8 (Jessie)
Posts: 747

Original Poster
Blog Entries: 1

Rep: Reputation: 172Reputation: 172
Thumbs up

Quote:
Originally Posted by unSpawn View Post
Then ensuring all users are properly educated about safe browsing / networking habits, logging, auditing and adjusting unwanted behaviour, denying Administrator privileges, making regular backups, filtering network access and deploying a good antivirus solution should be the first measures to take.
Setting a NTFS volumes readonly flag is like combating symptoms and not addressing the real cause(s).
Agreed. Unfortunately, you're preaching to the choir. :P
This is mostly my colleague's personal machines and I've long since given up explaining the basics to them.
Here in South Africa, most malware is distributed via USB flash-drives as most people don't have Internet. (except 3G, which is expensive)
For the same reason, most home computers never get updates.


Anyway, thanks for the tips.
 
Old 12-28-2014, 08:11 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Ah, I see the mess you're in... In that case I agree in whatever constitutes good defense.
 
  


Reply

Tags
ntfs, read only



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
1TB Segate Usb External Hard Drive jaypatience Linux - Hardware 3 06-20-2011 05:33 AM
on getting linux to recognize my 1TB usb external hard drive James rochelle Linux - Hardware 2 08-06-2009 04:28 PM
USB drive Read/Write - NTFS sp149 Linux - General 7 11-14-2007 04:11 PM
Lacie 1TB drive USB NFS Mount NTFS on Solaris haiders Linux - Networking 2 01-30-2007 03:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration