1 |
El mar, 03-05-2005 a las 22:54 +0200, Simon Stelling escribió: |
2 |
> Nice work, but do we really need that strong passwords? IMHO the |
3 |
> passwords generated by portage should be changed right after emerging |
4 |
> the piece of software anyway, although that might not be reality in many |
5 |
> cases :( I didn't have a closer look to the packages you listed, but i |
6 |
> hope those don't need a password for a unix account. Probably (just |
7 |
> guessing) they save the password in plain text anyway, so it wouldn't |
8 |
> matter that much... |
9 |
> |
10 |
> Perhaps I'm just totally wrong. |
11 |
|
12 |
Not, but you can't ensure that users will change them, you can warn |
13 |
them, you can bite them, you can kick them to do it, but they will end, |
14 |
maybe, not changing the generated password. |
15 |
|
16 |
Also, having the password in clear text has nothing to do with the |
17 |
permissions that allow or restrict a certain user from accessing it, |
18 |
that is, standard DAC (aka "standard Unix permissions") prevents users, |
19 |
at least theoretically, from accessing those files you don't want them |
20 |
to access, among that you can use MAC or any other more complex model to |
21 |
enforce such access restrictions (ie. by using SELinux, RSBAC... from |
22 |
Hardened Gentoo). |
23 |
|
24 |
(Check the dev-db/phpmyadmin bug regarding the wrong permissions of the |
25 |
SQL script with the password of the pma user). |
26 |
|
27 |
As less risks we assess, less responsibilities we have to manage |
28 |
regarding Q/A. |
29 |
|
30 |
Cheers, |
31 |
-- |
32 |
Lorenzo Hernández García-Hierro <lorenzo@×××.org> |
33 |
[1024D/6F2B2DEC] & [2048g/9AE91A22][http://tuxedo-es.org] |
34 |
|
35 |
-- |
36 |
gentoo-dev@g.o mailing list |