home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!caen!sol.ctr.columbia.edu!eff!ckd
- From: ckd@eff.org (Christopher Davis)
- Subject: Re: Experiences with John Haugh's Shadow Suite
- In-Reply-To: syscrc@pickle.gsu.edu's message of Fri, 13 Nov 1992 20:51:04 GMT
- Message-ID: <CKD.92Nov13185406@loiosh.eff.org>
- Sender: usenet@eff.org (NNTP News Poster)
- Nntp-Posting-Host: loiosh.eff.org
- Organization: Electronic Frontier Foundation Tech Central
- References: <syscrc.721687864@gsusgi1.gsu.edu>
- Date: Fri, 13 Nov 1992 23:54:09 GMT
- Lines: 18
-
- Randy> == Randy Carpenter <syscrc@pickle.gsu.edu>
-
- Randy> We are considering installing John Haugh's shadow password suite
- Randy> on our Silicon Graphics systems because of all the grief we get
- Randy> from our users about the proactive password program we
- Randy> installed.
-
- Shadowed passwords are not a replacement for a good (some would say
- fascist) proactive password program.
-
- NFS misconfigurations, buggy setuid programs, and the like can offer
- access to the shadow file. (I won't even go into the behavior most NIS
- installations have of giving the shadow file to the world.)
- --
- Christopher K. Davis | ``Usenet seems to run much like the Kif (or,
- <ckd@eff.org> EFF #14 | for the TV generation, Klingon) high command.
- System Administrator, EFF | Whoever takes action and can be heard wins.''
- +1 617 864 0665 [CKD1] | --Peter da Silva <peter@ferranti.com>
-