Re: Security Question: require root passwd for single user modelogin?


Subject: Re: Security Question: require root passwd for single user modelogin?
From: Graham Leggett (minfrin@sharp.fm)
Date: Tue Aug 29 2000 - 01:28:40 MDT


"Michael A. Peters" wrote:

> NOT requiring a password to boot single user is a Red Hat thing, and
> it sucks for physical security.

Access to the console, period sucks for physical security. Don't ever
assume just because single user mode is password protected that it will
stop anyone getting in.

Just boot off alternate media like a CD or floppy and mount the root
filesystem - you're in. If you password protect the BIOS, just take the
harddrive out and put it in another machine for a few minutes until
you're in. If you have physical access to the machine, you're in - the
best security is lock and key.

Regards,
Graham

--



This archive was generated by hypermail 2a24 : Tue Aug 29 2000 - 01:33:52 MDT