home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.kerberos
- Path: sparky!uunet!munnari.oz.au!bunyip.cc.uq.oz.au!brolga!ggm
- From: ggm@brolga.cc.uq.oz.au (George Michaelson)
- Subject: Re: New User Accounts
- Message-ID: <ggm.715407415@brolga>
- Sender: news@bunyip.cc.uq.oz.au (USENET News System)
- Organization: Prentice Centre, University of Queensland
- References: <9209020126.AA18513@Athena.MIT.EDU>
- Date: Wed, 2 Sep 1992 04:16:55 GMT
- Lines: 22
-
- smb@ulysses.att.com writes:
-
- >Put a ``passwd'' command in the initial .profile, and arrange for the
- >real default .profile (or .login if your religion runs that way) to
- >be installed by the initial version.
-
-
- We were hacked from an account created but never legally used within
- the non-expiry period. The initial password was admittedly insecure.
-
- Yes... the first command traced on the hacked account was to change the
- password.
-
- I now believe that in some circumstances you need to actually stand over
- the customer and MAKE them initialize the password to a secure value.
-
- -George
- --
- George Michaelson
- G.Michaelson@cc.uq.oz.au The Prentice Centre | There's no market for
- University of Queensland | hippos in Philadelphia
- Phone: +61 7 365 4079 QLD Australia 4072 | -Bertold Brecht
-