home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.next.sysadmin
- Path: sparky!uunet!darwin.sura.net!mips!zaphod.mps.ohio-state.edu!pacific.mps.ohio-state.edu!linac!uchinews!news
- From: eer1@midway.uchicago.edu(Paul Woods)
- Subject: Re: ROM Password
- Message-ID: <1992Jul22.213720.19160@midway.uchicago.edu>
- Sender: news@uchinews.uchicago.edu (News System)
- Reply-To: eer1@midway.uchicago.edu
- Organization: University of Chicago Computing Organizations
- References: <1992Jul16.152222.25152@ni.umd.edu>
- Date: Wed, 22 Jul 1992 21:37:20 GMT
- Lines: 43
-
- In article <1992Jul16.152222.25152@ni.umd.edu> louie@sayshell.umd.edu (Louis A.
- Mamakos) writes:
- > In article <1992Jul15.212656.27446@leland.Stanford.EDU> m@crito.Stanford.EDU
- (M Carling) writes:
- >
- > >Officially, resetting the ROM password (without having the old one) can
- > >only be performed by a trained service technician. The reason for this is
- > >that thieves would have an easier time selling their wares if knowledge of
- > >the procedure were widespread.
- >
- > Where in the world did you get the idea that the hardware password was
- > a theft deterrent? It certainly isn't an effective one if all you
- > have to do is remove the battery for an hour.
- >
- > The reason a hardware password on the NeXT is there for the same
- > reason it is on Sun platforms: to prevent people with physical access
- > to the machine from booting it into single-user mode. Once in single
- > user mode and running as root you bypass most of the security
- > mechanisms provided by the operating system and NFS (No File
- > Security).
- >
- > louie
-
-
-
- Anyone that is going to steal a next probably already knows how to remove the
- rom password. You do not even have to take the battery out for an hour or so.
- You could wipe out the password in a matter of seconds.
-
- I like your meaning of NFS (No File Security) Its not just NFS that has some
- major holes. I know someone (not me) that has found a way to gain root on almost
- any NeXT, even without an account on the machine. It was submitted to NeXT
- (because it is actually pretty simple) I hope that they fix it before 3.0 ships.
-
-
- Paul-
- --
-
-
-
- ____________________________________
- Paul R. Woods
- University of Chicago
-