home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ferkel.ucsb.edu!taco!gatech!emory!ogicse!das-news.harvard.edu!endor!adam
- From: adam@endor.uucp (Adam Shostack)
- Newsgroups: comp.security.misc
- Subject: Re: Two hackers caught tapping into Boeing, federal computers
- Message-ID: <1992Nov13.172230.3045@das.harvard.edu>
- Date: 13 Nov 92 17:22:30 GMT
- Article-I.D.: das.1992Nov13.172230.3045
- References: <1992Nov12.084549.5128@unix.brighton.ac.uk> <1992Nov12.142251.9131@hubcap.clemson.edu>
- Sender: usenet@das.harvard.edu (Network News)
- Organization: Aiken Computation Lab, Harvard University
- Lines: 22
-
- In article <1992Nov12.142251.9131@hubcap.clemson.edu> stehman%citron.cs.clemson.edu@hubcap.clemson.edu writes:
- >From article <1992Nov12.084549.5128@unix.brighton.ac.uk>, by ddv@unix.brighton.ac.uk (Domenico De Vitto):
- >> Any org. that has a _root_ password in _a_ dictionary gets all it deserves.
-
- >Would you like to require people to read c.s.m for a couple of months before
- >they're allowed to purchase a computer?
-
- No, I'd like too see vendors ship a decent version of password, say
- npasswd.
-
- I'd also like to see a two-three page readme on securing your
- workstation, and some slightly tougher defaults, like not putting that
- "+" in Sun's /etc/hosts.
-
- Closing a few simple holes probably makes an awful lot of difference.
-
-
-
- Adam Shostack adam@das.harvard.edu
-
- What a terrible thing to have lost one's .sig. Or not to have a .sig
- at all because of elections. How true that is.
-