When you think about a firewall, you think about a complicated tool big companies use to keep hackers out of their networks. And perhaps you think about the many movies where weird visuals are used to represent them being used and broken through. Nextcloud has the File Access Control app which acts as a bit of a firewall and while it helps protect businesses secrets, there are use cases for home users as well.
Introducing Two Factor Authentication
Two factor authentication has becoming quite popular in the last months/years. So you go ahead and enable all those fancy things on various websites you use. Note that they often provide you with a list of recovery keys! Where do you put those keys, to make sure you don’t ever lose them? There is this self-hosted cloud solution you use, with the slogan “a safe home for all your data“. And it sure can help with this!
By putting your keys on your Nextcloud you keep them to yourself. Yet, Nextcloud aims to make sharing easy. You don’t want to accidentally share your recovery keys, do you? Nor would you want your sync client on your phone to, all too easily, give access to these files. So is there an extra layer of protection possible, one that protects from accidental sharing or a stolen phone?
Protecting the keys
This is where the File Access Control app joins the party:
1. As a first step you assign the tag `Protected file` to your recovery files in the web UI.2. You go to `admin settings` > `File access control` and start a new rule group:
1. `File system tag` is tagged with `Protected file`2. `Request user agent` is not `Desktop client`
Your files can now no longer be downloaded and synced with the android client or a web browser.
This would disallow the client and only allow the web interface (and only Firefox!) from the local network.
Now to be sure the files are also not delivered to your laptop, you can add a second rule that only allows the Desktop client when the IP is the local IP of your Desktop PC which accesses the instance via the LAN rather then the internet:
1. `File system tag` is tagged with `Protected file`2. `Request user agent` is `Desktop client`3. `Request remote address` does not match IPv4 `192.168.176.42/32`
As you see, the File Access Control app can help ensure your data stays within the confines of your house or follows other rules which ensure you don’t accidentally make them available where you wouldn’t want them. Note that it is NOT a super secure solution, you can’t use it to replace https or other encryption solutions! But it can avoid mistakes through accidental sharing and such.
Post by Joas, main author of the File Access Control app
“Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat […]
“When we have welcoming communities of contributors, open source software gets better and more useful to everyone.” Limor Fried, Electrical Engineer, Inventor and Founder of open-source hardware company Adafruit We believe in this ideal and love to work with our community. We are always looking to involve more people in Nextcloud, bringing in their ideas, […]
Do you want to learn more about the leading Content Collaboration Platform? Nextcloud is an on-premises, integrated collaboration platform that can work for your organization or business in all sectors from Government, education, healthcare, and many other. Meet Nextcloud at exciting upcoming trade shows from Zukunftskongress and DMEA in Berlin to EdTech Congress Barcelona in […]
Over the last years Nextcloud Talk has developed in a fantastic productivity tool, enabling teams across the globe to communicate and collaborate in chat rooms, video meetings and webinars.
Hot on the heels of Nextcloud Hub 4, our desktop client now enables users who are running the latest Nextcloud to take advantage of its improved End-to-end encryption features!
After a complaint filed by Nextcloud on behalf of a coalition of dozens of European cloud tech providers in November 2021, the German Bundeskartellamt (federal antitrust authorities) has now begun an official investigation into Microsoft to assess if the company has a dominant position in the market.
Nextcloud users know the importance of integrating different systems and tools to create a seamless workflow. Nextcloud Enterprise allows you to integrate with Microsoft environments for file storage, user directory, Outlook, Sharepoint, Windows Desktop, MS Office online server, and Teams. And now, we are excited to announce a new addition to our lineup: the Nextcloud […]
“Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat […]
To aid government and business organizations migrating away from Microsoft 365, the Nextcloud Office team is looking for participants for UX studies. In particular, heavy users of Microsoft Office are encouraged to participate and provide their input so the team can identify and address the key blockers for migration. Aim of the study Nextcloud is […]
We save some cookies to count visitors and make the site easier to use. This doesn't leave our server and isn't to track you personally!
See our Privacy Policy for more information. Customize