 |
 |
Another Apple security flaw?
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2001
Location: Canaduh
Status:
Offline
|
|
I created a "managed" guest account with restricted access to certain applications. I disabled Mail because I wanted users of this account to use webmail only.
I logged into the account, double-clicked Mail, and sure enough, it said I didn't have the privileges to do this.
I went out for a while during which a friend of mine used my computer to send out resumes (using the guest account). When I came back, I noticed that Mail.app was running.
WTF?
I also noticed that Safari was running. I quit Mail.app and loaded up a page in Safari that contained a mail link. When I clicked the link, Mail.app launched even though I had disabled it System preferences. The same thing occurred with other browsers.
I consider that a security flaw (albeit a very minor one) especially since Apple's own browser circumvents the system's security settings.
|
|
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Feb 2000
Location: Washington, DC
Status:
Offline
|
|
Yah, I hear this is a known issue. The way to resolve it is to move all the applications in to your own personal applications account and remove them from the main applications section.
I'm rather sure there are other ways to make the system more ridged as well.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Oct 2001
Location: Yokohama, Japan
Status:
Offline
|
|
Originally posted by mitchell_pgh:
I'm rather sure there are other ways to make the system more ridged as well.
What, like Ruffles potato chips? I don't know about that, but you could probably make it rigid.
Maybe you could try changing the default mail app, or the app that handles mailto.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2001
Location: Canaduh
Status:
Offline
|
|
Originally posted by wataru:
What, like Ruffles potato chips? I don't know about that, but you could probably make it rigid.
Maybe you could try changing the default mail app, or the app that handles mailto.
I installed a preference pane called Default Apps that allowed me to disable the "mailto" handler for that account. It did the trick. Hopefully, Apple will fix this in the future.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Oct 2001
Location: Yokohama, Japan
Status:
Offline
|
|
You can also do it with IE (if you haven't deleted it already), so there is a sort-of-built-in way to do it. I agree, though, that this is a pretty big oversight. Hopefully Apple will fix it. Have you reported it?
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2001
Location: Canaduh
Status:
Offline
|
|
Originally posted by wataru:
Have you reported it?
I submitted it via the OS X feedback page.
|
|
|
| |
|
|
|
 |
 |
|
 |
|
|
|
|
|

|
|
 |
Forum Rules
|
 |
 |
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is Off
|
|
|
|
|
|
 |
 |
 |
 |
|
 |
|