Let’s say you have access to a remote machine and use it to copy backups occasionally, eg with rsync. Your local machine has credentials stored that allow write access on the remote machine, however if the local account was compromised that could also allow access to the remote machine and the data stored there.

How can you grant access to an account to write remotely, but also protect the data from this account? One possibility could be to change the permissions on the data after it is copied to prevent deletion/interference, although I’m just making this up. Is there a standard practise for this?

  • HelloRoot@lemy.lol
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    Are they? I thought they only write/modify/delete data to the fs, not change the fs itself.

    • groet@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Yeah precice phrasing ia hard sometime. I was refering to delete/modify of files as “changes to the fs”. Not sure how changing the actuall fs would be relevant to the backup question.

      OP needs a restricted shell that can take backup data and write it to disk but not be able to modify anything that is already there. Nano and rsync can both do that.