Protected Data Folders doesn't work as help files claim [V7B][HF][M810]

Not necessarily if nothing inside it is meant to be changed, but honestly we can stay here and make guesses all we want but the truth is that we just won’t know until a developer or Melih or someone that actually knows comments on this, and judging by the fact that we are going back and forth making guesses I’m going to make a somewhat educated guess and say neither of us knows what the real intentions for this feature is.

Obviously for certainty that’s true Sanya, but our chances there are limited. Look what trouble I am having contacting anyone to get authorisation for release of more info on new features!

For me now the main uncertainty is whether there are any permissions differences between this and protected folders.

Best wishes

Mike

I’ll try and look into it.

Thanks Sanya very much

Mouse

Okay so now I’ve tested the difference between Protected Files/Folders and Protected Data Folders, the video can be found here: https://www.youtube.com/watch?v=tkAlZ8Zgq8Q

Please note, when I say Test.txt is or is not added to Protected Data Folders, I of course mean the folder that Test.txt resides in, i.e […]\Test\

[ol]- Scenario 1: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | neither of the files/folders are added to Protected Files/Folders or Protected Data Folders | HIPS - Safe Mode / BB - Off

[li]Get alert that Test.bat tries to launch conhost.exe

  • Test.txt is removed without alert
    [/li]

  • Scenario 2: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | Test.txt added to Protected Files/Folders but not Protected Data Folders | HIPS - Safe Mode / BB - Off

[li]Get alert that Test.bat tries to launch conhost.exe

  • Get alert that Test.bat is trying to modify a protected File/Folder Text.txt (Clicking allow will delete the file, clicking block will not allow deletion)
    [/li]

  • Scenario 3: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | Test.txt not added to Protected Files/Folders but added to Protected Data Folders | HIPS - Safe Mode / BB - Off

[li]Get alert that Test.bat is trying to launch conhost.exe

  • Get alert that Test.bat wants direct disc access (Clicking allow will delete the file, clicking block will not allow deletion)
    [/li]

  • Scenario 4: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | Test.txt added to Protected Files/Folders and added to Protected Data Folders | HIPS - Safe Mode / BB - Off

[li]Get alert that Test.bat tries to launch conhost.exe

  • Get alert that Test.bat wants direct disc access (Clicking allow will not directly allow deletion)

  • Get alert that Test.bat is trying to modify a protected File/Folder Text.txt (Clicking allow will delete the file, clicking block will not allow deletion)
    [/li]

  • Scenario 5: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | neither of the files/folders are added to Protected Files/Folders or Protected Data Folders | HIPS - Safe Mode / BB - Partially Limited

[li]Test.bat deletes Test.txt without any issues
[/li]

  • Scenario 6: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | Test.txt added to Protected Files/Folders but not Protected Data Folders | HIPS - Safe Mode / BB - Partially Limited

[li]Get “Access is denied”
[/li]

  • Scenario 7: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | Test.txt not added to Protected Files/Folders but added Protected Data Folders | HIPS - Safe Mode / BB - Partially Limited

[li]Claims can not find […]\Test\Test.txt (Test.txt not removed)
[/li]

  • Scenario 8: […]\Test\Test.bat tries to delete […]\Test\Test.txt | Test.bat is an unknown application | Test.txt added to Protected Files/Folders and added Protected Data Folders | HIPS - Safe Mode / BB - Partially Limited

[li]Claims can not find […]\Test\Test.txt (Test.txt not removed)
[/li][/ol]

Conclusion: When using BB the end result is the same for both, neither is allowed to touch the files. When using HIPS the difference is that with Protected Data Folders you get an alert for direct disc access and with Protected Files/Folders you get an alert for the specific protected file, i.e Protected Files/Folders is more informative.

Thanks Sanya. Very comprehensive testing. The direct data access is in my view a wording bug (and known) - its ‘data access’ but not ‘direct’.

So now we know… :slight_smile:

Either way it seems like it’s only a less detailed version of Protected Files/Folders since Protected Files/Folders actually say what file it is while Protected Data Folders simply give an “All access” alert, if that makes sense.

Yes that makes sense, and ties in with the idea of one being a simplified version of the other.

I guess there is where we disagree, I don’t think it makes sense, it’s not simplified, just less information in one alert which is if anything harder to answer since you don’t know what files it’s about, i.e no it isn’t simplified in my opinion, besides I’ve seen people asking for similar features as the help files indicate the Protected Data Folders should be like but I’ve never seen anyone ask for this.

In my opinion it makes no sense and if anything it causes confusion, normal users wouldn’t know what the difference is and hence be more confused than if it was only one.

So I think (hope) it’s a bug with how Protected Data Folders, you think it’s the help file that is wrong, now I think it’s just a waiting game.

I agree Sanya, that a facility that enabled a block for all processes with an access list, and maybe with read-block as optional too, perhaps user-based would add more.

(In a way it would make standard OS facilities more accessible. You could emulate some or all of this using OS facilities, but its complex and confusing).

But that’s not what we have, so as you say there is not much more to be said at the moment. But you could make a separate wish for the uprated facility if you want.

Let’s leave it here (or with a new wish) at the moment.

Best wishes

Mike

I believe that explains the situation, i.e you were right, it was a help file issue, hopefully they fix it when it’s put up again.

Thanks Sanya. It was 50/50 who would be right. Probably I’ve puzzled over the help file more often than you :slight_smile:

So I guess this can be moved to resolved? Assuming they’ll fix the help file? ???

Yes I have retired it - Chiron will move it when he does his next sweep.

Documentation editor notified. Thanks very much Sanya. Mike.

As suggested I will now move this to Resolved.

Thanks.