home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.sys.sgi.admin:128 comp.sys.sgi:18558
- Newsgroups: comp.sys.sgi.admin,comp.sys.sgi
- Path: sparky!uunet!gumby!destroyer!wsu-cs!igor.physics.wayne.edu!atems
- From: atems@igor.physics.wayne.edu (Dale Atems)
- Subject: Re: security concerns revisted
- Message-ID: <1993Jan7.155721.7859@cs.wayne.edu>
- Sender: usenet@cs.wayne.edu (Usenet News)
- Organization: Wayne State University, Detroit, MI
- References: <ui2dla0@zuni.esd.sgi.com> <C0GEH4.2KJ@helios.physics.utoronto.ca> <uij5h2g@zuni.esd.sgi.com>
- Date: Thu, 7 Jan 1993 15:57:21 GMT
- Lines: 35
-
- In article <uij5h2g@zuni.esd.sgi.com> olson@anchor.esd.sgi.com (Dave Olson) writes:
- >
- >I maintain (and a number of people disagree with me), that you *have*
- >to ship an open root, and given that, anybody who can't scan a
- >*15 line* password file to notice the other accounts that have no
- >passwords is unlikely to do anything about root either. If they
- >don't secure root, nothing else matters. We can start all of these
- >arguments all over again, but I maintain (both as a system admin in
- >a number of environments, and as a tech support resource in 4 compainies)
- >that we would be *crazy* as a company to do anything else.
-
- With all due respect, Dave, I have to disagree here. Most people are
- sensible enough to protect root, but either aren't aware of the other
- open accounts or put off learning how to protect them without giving up
- the ability to share resources over the network (like remote printers,
- etc.). People buy systems to solve problems, and many sites (like ours)
- don't have full-time system administrators. The people who set up the
- systems aren't idiots, they're expected to set the systems up and then
- go back to writing proposals. Learning about security issues gets put
- on the back burner along with getting system software upgraded, getting
- clocks synched to a reliable source, diagnosing network slowdowns...
-
- >As has been discussed here every time this has come up (and as Vernon
- >mentioned in this same thread), the best thing would be to have a script
- >that runs after install, similarly to the autoconfig and confmsg scripts,
- >that asks the user if they want to setup a secure system, and walks them
- >through it in a script. That may still happen for a future release.
-
- Excellent idea. How far in the future are we talking about?
-
- ------
- Dale Atems
- Wayne State University, Detroit, MI
- Department of Physics and Astronomy
- atems@igor.physics.wayne.edu
-