1 |
Still, it would perhaps be somewhat comforting to be able to disable |
2 |
EASY access to a "mission critical" system. |
3 |
|
4 |
What about further disabling of access to /etc/passwd? Does SELinux |
5 |
take any such steps? (Ok, I could look into this by reading TFM. |
6 |
Apologies). |
7 |
|
8 |
Alan |
9 |
|
10 |
On 4/16/06, Alexander Skwar <listen@×××××××××××××××.name> wrote: |
11 |
> Alan E. Davis wrote: |
12 |
> > I helped a friend install Ubuntu GNU/Linux on his laptop, he left |
13 |
> > town, forgot his passwords, and I promised to breakin for him, so he |
14 |
> > can re-do his passwords. Told him all I have to do is run Knoppix, |
15 |
> > access his partition, and delete the little x in the password file. |
16 |
> > Then he would reset his root password in be back in business. |
17 |
> > |
18 |
> > He felt betrayed. I understand why, I think: what's secure about |
19 |
> > GNU/Linux if anyone can boot the system and reset his passwords? |
20 |
> |
21 |
> That's NOT a Linux problem. If you've got physical access, |
22 |
> you can easily break in (same for Windows, BTW). |
23 |
> |
24 |
> > I said, Dunno. I'll ask on the Gentoo list. |
25 |
> > |
26 |
> > How can anyone easily avoid the problem of anyone being able to access |
27 |
> > the guts of his machine using a live CD? |
28 |
> |
29 |
> Remove CD-Rom. |
30 |
> Put Computer in a solid box which cannot (easily) be opened, |
31 |
> so that it's "impossible" to attach an external CD-Rom. |
32 |
> |
33 |
> > I already thought of one: |
34 |
> > use the BIOS to disallow booting from a CD or Floppy, and set a |
35 |
> > password on the BIOS. |
36 |
> |
37 |
> Most BIOS support either a "master password" |
38 |
> or a way to reset a password (some pins on the |
39 |
> motherboard). |
40 |
> |
41 |
> > Don't know whether all BIOSes will allow this, |
42 |
> > and anyway, isn't it possible on a lot of motherboards to short out |
43 |
> > the EPROM and thus reset the password of the BIOS? |
44 |
> |
45 |
> Yes. |
46 |
> |
47 |
> Alexander Skwar |
48 |
> -- |
49 |
> Hey Satan, didja hear the news? A war just broke out up on earth. |
50 |
> |
51 |
> Meet Saddam Hussein, my new partner in evil. |
52 |
> -- |
53 |
> gentoo-user@g.o mailing list |
54 |
> |
55 |
> |
56 |
|
57 |
-- |
58 |
gentoo-user@g.o mailing list |