5
My father owns a small business and has to hand over several year's worth of financial documents to his insurance's auditor. He's asked me to go through and make sure everything is "read-only" so the data (the files) absolutely, positively cannot be modified or manipulated (he's a bit paranoid).
We're talking about 20,000 documents (emails, spreadsheets, etc.).
My first inclination was to place everything inside of one root folder ("mydadsdocs/") and then write a script that recursively traversed its directory subtree and set the file permissions to read-only.
But then I got to thinking: that's a lot of work for me to do to satisfy an old man who is just being paranoid, and afterall, if someone really wanted to modify a read-only file, it would be pretty easy to change file permissions anyways, soo....
Is there like a checksum I could run on the root folder, something that was very quick and easy, and that would basically "stamp" the data in that folder so if someone did change it, my father would have someone of knowing/proving it?
If so, how?
If not, any other recommendations that are quick, cheap (free) and effective?
Checksums are of little use if they can also be changed. Or they are stored separately in a safe place? Still, I think the correct tool for this scenario is cryptographic signatures. (Unless an adversary knows the private key, he cannot forge signatures of these files) – Display Name – 2015-12-31T14:48:07.287
Do you have access to Powershell on the machine? – EBGreen – 2011-06-27T15:23:54.517
I guess (it's his machine and he'll give me access to whatever I need) but I've never worked in PS before – Kim – 2011-06-27T15:29:34.993
I suppose you could zip the directory and hash the zip file. Better yet, cryptographically sign the zip file (which includes hashing it). – Joey Adams – 2011-06-27T15:37:34.130
Thanks Joey - how could I hash the zip, is there a utility I need to download or is that something I could call from the command line? – Kim – 2011-06-27T15:38:48.153
I think what he means by hashing the zip file is to run an md5 checksum against it. There are many md5 tools out there (both command line and graphical). – Matrix Mole – 2011-06-27T16:52:53.930
Please note that it has become rather easy to generate MD5 collisions, especially if the file format allows it (.zip does). Use a stronger hash. – user1686 – 2011-12-15T20:29:16.637