Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - Two versions of Vista on same HD - Security Issue

Reply
 
Old 10-09-2006   #1 (permalink)
Tim Starid


 
 

Two versions of Vista on same HD - Security Issue

Allo,

I have two different builds of Vista on the same drive, separate partitions.
I noticed that if I'm running one and want to access data on the other, I can
just navigate to that drive, and only run into a warning when I attempt to
access a user's private foulder. I can click the box and the warnign goes
away, giving me access to the user's files. Since I'm not the administrator
of that partition/user group shouldnt it block me? I dont have any encryption
set up yet, but I'd think since vista does this in it's own instance,
connecting to a different instance of vista should require you to be in the
same group/permissions set.

My System SpecsSystem Spec
Old 10-09-2006   #2 (permalink)
Jimmy Brush


 
 

Re: Two versions of Vista on same HD - Security Issue

Hello,

The reason this is possible is due to the way Windows handles well-known
group permissions. The well know groups in Windows, such as Users,
Administrators, etc, are recognized on the permissions for the files/folder
regardless of what installation of Windows created the files/folder.

So, if you have a file that was created in one installation of Windows that
gave Administrators full control over it, then logged in to a DIFFERENT
installation of Windows as an administrator, you would have full control
over that file, even though it was created in a different installation of
Windows.

The same thing is happening in your case - you are accessing a file/folder
that you SPECIFICALLY do not have access to, but "Administrators" do - so
the system asks you if you want to invoke your administrator powers and give
yourself access to the folder.

You are correct in that this does pose a slight security risk - however, the
benefits far outweight the risks. If this did not work the way I described,
you would not be able to dual boot between instances of Windows effectively,
as you would be denied read AND write access to ALL files made from any
other instance of Windows.

Also, keep in mind that if one has physical access to the hard disk, one can
bypass any file-based security mechanism with the right tool - so the actual
security of the files of another installation of windows when another
operating system is running on that computer is pretty poor, regardless of
what permissions are in place.

--
- JB

Windows Vista Support Faq
http://www.jimmah.com/vista/

My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Big Security Hole in All IE Versions System Security
Vista security and infection issue Vista security
Vista Security - Certificate Issue? Vista General
Vista - Security Issue - 2 Admin profile on 1 computer Vista account administration
OEM versions and Full Versions of Vista Vista installation & setup


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46