Gentoo Archives: gentoo-user

From: Alan McKinnon <alan.mckinnon@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Recovering root password
Date: Tue, 25 Mar 2008 08:26:25
Message-Id: 200803251025.17569.alan.mckinnon@gmail.com
In Reply to: Re: [gentoo-user] Recovering root password by Liviu Andronic
1 On Tuesday 25 March 2008, Liviu Andronic wrote:
2 > >  But you can boot from a LiveCD, mount your harddrive, chroot and
3 > > then give root another password.
4 >
5 > But then, conventional passwords are as useless. One needs no more
6 > than physical access to the computer, a LiveCD and a couple minutes
7 > in order to become the super user of your system. Basically, the
8 > password seems useful only to know whether anyone has changed it
9 > behind your back.
10
11 Let me guess - you own a notebook and most of your exposure to running a
12 computer is limited to that, and you have never administered a real
13 server somewhere, right?
14
15 It's very very easy to keep your servers safe from physical access
16 attacks - make sure the bad guys can't touch it. This is so easy to do
17 it's laughable - we use a locked door. The only people who have a key
18 are those who have to root password anyway.
19
20 On a notebook, there isn't an OS in existence that is immune to a
21 LiveCD. If this concerns you, apply some biometrics and encrypted
22 filesystem patches. Or stop using notebooks. Or stop using computers
23 that someone else can touch.
24
25 --
26 Alan McKinnon
27 alan dot mckinnon at gmail dot com
28
29 --
30 gentoo-user@l.g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Recovering root password Neil Bothwick <neil@××××××××××.uk>
Re: [gentoo-user] Recovering root password Dirk Heinrichs <dirk.heinrichs.ext@×××.com>