?? ExtHD OS admin-acct can access user files on Mac boot device!

Eii! Surprising and welcome revelation is that when booted into OSX 10.9.5 on an external drive, I can (when in admin acct in that OS) access & copy data in a standard-user's account residing in the OSX 10.9.5 OS of the boot device (both a MBP & a Mac Mini).



How is this possible? All the aggravation a Mac puts one through with discrete user accounts and yet, I can breeze right into a standard-user account's data residing on the boot device.



The external drive OS first used was cloned from a Mac HD. Theorizing that might be why I could so readily access a user's file on the boot device (even tho acct names were different), I did a fresh install of 10.9.5 (from thumb installer) onto the external drive and set up admin & std accounts with totally different names. Made no difference.



I found that only the admin acct on the external drive's OS (into which I had booted from an initially fully-powered-off Mac) could read data in a standard-user's account. However, when signed into a standard account in the booted up external drive's OS, I could still readily access the underlying MacHD system and library files.



I *lock* up whereever I can, so I don't have things such as automatic login enabled. Everything is passwroded up the wazoo. Frankly, given the headaches with user file ownsership of having each user account so locked up, I am really ticked off that I'm seeing wide-open user files and ready access to the HD of the Mac used for booting into external drive.



Is this normal behavior? And is there anyway to close the gate more between the two devices in terms of file accessf from the external drive?



I ask this because I had (sigh, naively, it appears) hoped to use the external drive's OS for surfing internet only -- no data or sensitive info on that drive. My hope was that if again caught by malware, it would be less likely to infect my Mac,and I could wipe the external drive (having so little data invested in it).

MacBook Pro, OS X Mavericks (10.9.5), 2.2Ghz Iintel Core i7, 4GM RAM

Posted on Aug 18, 2015 9:51 PM

Reply
4 replies

Aug 18, 2015 9:55 PM in response to mackedout

1. Either the volume is set to ignore permissions, or the individual folders allow the administrator account access, or the administrator account and the account you accessed have the same numeric UID.

2. Enable FileVault. By default, anyone who has an administrator user account and password can access any unencrypted data on the system; in some cases, they'll need to supply the password again to get at the files.


(131979)

Aug 24, 2015 5:15 PM in response to Niel

Thanks Niel. I don't know how to determine what the UID is (don't even know what an UID is). The files accessed may have permission for all to at least read, but seems to me even an admin user from another OS & volume shouldn't be able to get to folder level of a user on the MacHD. He should be greeted with a red minus on the system's Document folder for the user. I plan to erase and reformat the MacHD anyway. I'll see what happens after starting over. You've brought to light file permissions that were a surprise as I usually don't set permisson to allow every one to read files. Need to get busy correcting that. Thanks again.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

?? ExtHD OS admin-acct can access user files on Mac boot device!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.