LINUX.IE, website of the Irish Linux Users' Group
Tux rules!

   
Home
New Users
Articles
Download
Projects
Community
Vendors

  Print Version
Email to...
 
Archives:


planetILUG

Recent News

News Archive


Join the
ILUG
on FaceBook


Join the
ILUG
on LinkedIn


Join the
ILUG SETI
Group



















 
 :: Mailing Lists

[ILUG] [OT] Security permissions for passwd

[ILUG] [OT] Security permissions for passwd

Philip Reynolds phil at redbrick.dcu.ie
Tue Jun 20 17:04:56 IST 2000


David Murphy's [drjolt+ilug at redbrick.dcu.ie] 33 lines of dribble included:
:>Quoting <NBBBIGEGHIGMPCNKHCECCEPNDKAA.kenn at bluetree.ie>
:>by Kenn Humborg <kenn at bluetree.ie>:
:>> > you don't even need a recovery disk.  and pw protecting lilo is pointless
:>> > since you can either use a recovery disk or just rip out the disk and
:>> > mount it elsewhere.
:>> > 
:>> > repeat:  must. have. physical. security. to. be. secure.
:>> 
:>> I disagree.  A locked case that's physically tied down with
:>> no floppy or CD drive could have LILO and single-user
:>> passwords and be secure.  (And a BIOS password...)
:>
:>Wouldn't the lock on the case count as physical security? Physical
:>security can be anything from a padlock to a vault.

Taking a guess that the point he was disagreeing with was that it's pointless
password protecting LiLo. 
On Kenn's point if you don't password protect LiLo, anyone with
physical access to your machine for about T (t being time it takes to reboot
plus 1 minute) minutes can have ur box backdoored. It could be by chance they
get in front of your box (not everyone carries bootdisks around with them, ok
well before last Saturday not everyone ;P) and riping the hard drive out
wouldn't be an option. It's narrowing down options, not a total preventative
security measure.

-- 
[---------
  Philip Reynolds                | Errors have occurred..
  Redbrick Systems Administrator | We won't tell you where or why.
  phil at redbrick.dcu.ie           | Lazy Programmers.
                                                    ---------------]




More information about the ILUG mailing list
Read this without the formatting.
                                                                                                    

 

Hosted by HEAnet


Maintained by the ILUG website team. The aim of Linux.ie is to support and help commercial and private users of Linux in Ireland. You can display ILUG news in your own webpages, read backend information to find out how. Networking services kindly provided by HEAnet, server kindly donated by Dell. Linux is a trademark of Linus Torvalds, used with permission. No penguins were harmed in the production or maintenance of this highly praised website. Looking for the Indian Linux Users' Group? Try here. If you've read all this and aren't a lawyer: you should be!
RSS Version
Powered by Dell