home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!usc!hacgate!nuntius
- From: mark@bart.hac.com (Mark Johnson)
- Newsgroups: comp.sys.sgi
- Subject: Re: Should be in FAQ: Security holes in default /etc/passwd file
- Message-ID: <24637@hacgate.SCG.HAC.COM>
- Date: 7 Jan 93 12:58:58 GMT
- References: <1992Dec24.193457.16465@u.washington.edu>
- <ui4bjgk@rhyolite.wpd.sgi.com> <C0GKHt.18s.2@cs.cmu.edu>
- <uij5h2g@zuni.esd.sgi.com>
- Sender: news@hacgate.SCG.HAC.COM
- Organization: Hughes Training, Inc.
- Lines: 27
- X-UserAgent: Nuntius v1.1
-
- Re: security concerns revisted
-
- Perhaps I don't understand, but the change that DEC made in the VMS
- installation procedure after getting burned badly several years ago was
- quite modest and was also quite effective. If you are not aware of the
- method they used, they added several prompts to the system installation
- procedure that asked for passwords for the default accounts like SYSTEM,
- FIELD, and SYSTEST. If you tried to enter MANAGER, SERVICE, and UETP (the
- original default passwords for those accounts), the procedure would ask
- again for an original, non-null, password.
-
- Of course, DEC has greatly strengthened the security of VMS since then
- and for a price (:-<) can provide more extensive security capabilities
- and periodic rechecks of system security items.
-
- I don't expect SGI developers to go to the lengths that DEC has in making
- a full featured secure operating system. I do expect SGI developers to
- make reasonable efforts at providing a secure environment for me to do my
- own development, and that the deliverable systems we sell can be made
- secure to meet my customers needs. I think it is reasonable that SGI
- developers add some simple changes to system installation procedures that
- make the systems more secure. I also think it is reasonable that periodic
- security checks be made automatic for a nominal fee [though I would think
- that several people reading this news feed alreay have such things for
- free].
-
- --Mark Johnson <MARK@BART.HAC.COM>
-