PDA

View Full Version : Serv LT - Managing Accounts


David McRell
06-15-2005, 03:18 PM
We just bought the Serv LT.

Big Comment: With the LT model having just one (1) Standard account, which is also the administrator account ... if I give that login to someone for the purposes of adding accounts, they can also access and edit every setting on the device.

boo!

Sending deliveries as the appliance owner is easy and painless enough - no extra accounts needed. The DigiDelivery sales pitch, however, states ...


no need for recipients to enter IP addresses, usernames, or passwords.



True, but you do need to create accounts and passwords in order for a client (guest) to send you anything. So, if some new client needs to send us some material on a whim, they cannot simply do so without an 'administrator' creating an account on the appliance, conjuring up a password, and then relaying this and the appliance's address back to the client.

hmmm - makes perfect sense coming from a sys admin's perspective, but it somewhat contradicts the whole sales pitch.

I would really like to see this upgraded so the one (1) standard DigiDelivery account is not also the 'root' access for device network settings, admin password, etc.

Thanks

Gordon Lyon
06-17-2005, 04:11 PM
if some new client needs to send us some material on a whim, they cannot simply do so without an 'administrator' creating an account



While I understand the convenience of being able to post files without having an account, I think the risks far outweigh the value. The Internet is full of people who search out poorly protected servers to use for their own storage and transfers. Moreover, in many countries the owner of a server is liable for its contents, meaning that you could be prosecuted if someone put little nasties on your DigiDelivery server without your knowledge. This is why you'll find virtually no FTP site or networked storage that does not require an administrator-created account.

Having said that, we will definitely consider your request to have the standard account be separate from the admin account. And definitely bring up other suggestions as they come to you!

Thanks, Gordon

David McRell
06-17-2005, 06:26 PM
Thanks for considering the idea of having the one (1) standard account distinct from an administration account. The two product tier, LT offering either one solitary account or GT with unlimited accounts, is a bit sharp.


While I understand the convenience of being able to post files without having an account, I think the risks far outweigh the value.



Granted. I realize the prime directive was to remove the possibility of an outside client using the studio's server for sharing files with unauthorized parties.

That being said ... As the owner of the device ... we (a Standard account) can create a delivery for anyone with an email address, and the URL sent in that message contains all the information needed to receive the delivery.

A similar approach could be taken for a 'one shot' client-to-server delivery. The Standard account sends an email to a client. This message contains a link that authorizes that guest to one delivery or a limited window of time for sending deliveries. No hosts, usernames, or passwords.

For ongoing deliveries, a Guest would need an account as it is handled now.

Regards

Gordon Lyon
06-17-2005, 07:15 PM
Thanks for the feedback, David. We've discussed this exact idea in the past and agree it would be great to add. Of course, I can't promise anything or I get beaten severely about the head...