Gentoo Archives: gentoo-user

From: "Alan E. Davis" <lngndvs@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Security from non-authorized logins
Date: Sun, 16 Apr 2006 13:21:45
Message-Id: 7bef1f890604160613k2df91a7cs312869a0f246c937@mail.gmail.com
In Reply to: Re: [gentoo-user] Security from non-authorized logins by Alexander Skwar
1 Still, it would perhaps be somewhat comforting to be able to disable
2 EASY access to a "mission critical" system.
3
4 What about further disabling of access to /etc/passwd? Does SELinux
5 take any such steps? (Ok, I could look into this by reading TFM.
6 Apologies).
7
8 Alan
9
10 On 4/16/06, Alexander Skwar <listen@×××××××××××××××.name> wrote:
11 > Alan E. Davis wrote:
12 > > I helped a friend install Ubuntu GNU/Linux on his laptop, he left
13 > > town, forgot his passwords, and I promised to breakin for him, so he
14 > > can re-do his passwords. Told him all I have to do is run Knoppix,
15 > > access his partition, and delete the little x in the password file.
16 > > Then he would reset his root password in be back in business.
17 > >
18 > > He felt betrayed. I understand why, I think: what's secure about
19 > > GNU/Linux if anyone can boot the system and reset his passwords?
20 >
21 > That's NOT a Linux problem. If you've got physical access,
22 > you can easily break in (same for Windows, BTW).
23 >
24 > > I said, Dunno. I'll ask on the Gentoo list.
25 > >
26 > > How can anyone easily avoid the problem of anyone being able to access
27 > > the guts of his machine using a live CD?
28 >
29 > Remove CD-Rom.
30 > Put Computer in a solid box which cannot (easily) be opened,
31 > so that it's "impossible" to attach an external CD-Rom.
32 >
33 > > I already thought of one:
34 > > use the BIOS to disallow booting from a CD or Floppy, and set a
35 > > password on the BIOS.
36 >
37 > Most BIOS support either a "master password"
38 > or a way to reset a password (some pins on the
39 > motherboard).
40 >
41 > > Don't know whether all BIOSes will allow this,
42 > > and anyway, isn't it possible on a lot of motherboards to short out
43 > > the EPROM and thus reset the password of the BIOS?
44 >
45 > Yes.
46 >
47 > Alexander Skwar
48 > --
49 > Hey Satan, didja hear the news? A war just broke out up on earth.
50 >
51 > Meet Saddam Hussein, my new partner in evil.
52 > --
53 > gentoo-user@g.o mailing list
54 >
55 >
56
57 --
58 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Security from non-authorized logins Alexander Skwar <listen@×××××××××××××××.name>
Re: [gentoo-user] Security from non-authorized logins Rumen Yotov <rumen@××××××.org>