summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-dev/2012-June/016160.html
blob: dd20b66a7238a0b7c362472fbed5d5ebe3867a5a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
 <HEAD>
   <TITLE> [Mageia-dev] bug, omission or feature
   </TITLE>
   <LINK REL="Index" HREF="index.html" >
   <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20bug%2C%20omission%20or%20feature&In-Reply-To=%3C4FCCF918.4010505%40linuxcabal.org%3E">
   <META NAME="robots" CONTENT="index,nofollow">
   <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
   <LINK REL="Previous"  HREF="016149.html">
   <LINK REL="Next"  HREF="016176.html">
 </HEAD>
 <BODY BGCOLOR="#ffffff">
   <H1>[Mageia-dev] bug, omission or feature</H1>
    <B>Richard Couture</B> 
    <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20bug%2C%20omission%20or%20feature&In-Reply-To=%3C4FCCF918.4010505%40linuxcabal.org%3E"
       TITLE="[Mageia-dev] bug, omission or feature">rrc at linuxcabal.org
       </A><BR>
    <I>Mon Jun  4 20:06:16 CEST 2012</I>
    <P><UL>
        <LI>Previous message: <A HREF="016149.html">[Mageia-dev] bug, omission or feature
</A></li>
        <LI>Next message: <A HREF="016176.html">[Mageia-dev] bug, omission or feature
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#16160">[ date ]</a>
              <a href="thread.html#16160">[ thread ]</a>
              <a href="subject.html#16160">[ subject ]</a>
              <a href="author.html#16160">[ author ]</a>
         </LI>
       </UL>
    <HR>  
<!--beginarticle-->
<PRE>I'm in full agreement, however the point of my initial post was not to 
obtain an evaluation of the merits of being able to, as part of the 
install as was the case in versions previous to system D, but to ask if 
a mechanism, providing the same function as was previously available, 
through msec or whatever, is in the plans...

I value(d) this option and think that replacing it with whatever 
mechanism is necessary would be an asset to Mageia, whereas I now view 
it's lack of function as a loss.

Perceptions are really important as can be seen in the various reviews 
which condemn for seemingly irrelevant details...

Thanks





Richard



On 06/04/2012 06:10 AM, Buchan Milne wrote:
&gt;<i> On Sunday, 3 June 2012 17:52:47 Colin Guthrie wrote:
</I>&gt;<i>
</I>&gt;<i>  &gt; On the whole, this kind of &quot;security&quot; is basically bullshit anyway.
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i> You can't make that assessment without understanding the rest of the
</I>&gt;<i> security environment.
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i>  &gt; It
</I>&gt;<i>
</I>&gt;<i>  &gt; might make things a tiny bit harder, but if you can get into the
</I>&gt;<i>
</I>&gt;<i>  &gt; bootloader to append a 1 on the command line,
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i> Maybe you *can't* append anything you like to the command-line. Maybe
</I>&gt;<i> the bootloader configuration has a 'boot single' option, which should
</I>&gt;<i> require entry of the root password to access the system.
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i>  &gt; you can also append
</I>&gt;<i>
</I>&gt;<i>  &gt; init=/bin/bash too which totally bypasses everything too.
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i> Not if the bootloader configuration is password protected (IOW, you can
</I>&gt;<i> boot any configured option, but if you want to modify anything, you need
</I>&gt;<i> to provide a password, different from the root password).
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i>  &gt; So while it's
</I>&gt;<i>
</I>&gt;<i>  &gt; maybe a nice idea, for all practical purposes, it's not any kind of real
</I>&gt;<i>
</I>&gt;<i>  &gt; security anyway, so don't rely on it!
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i> No security implementation relies on a single control being in place. A
</I>&gt;<i> numebr of modern security best practices have thousands of controls, and
</I>&gt;<i> the requirement for a password to be entered to boot single is almost
</I>&gt;<i> always one of them, and a requirement for a bootloader password is
</I>&gt;<i> usually another.
</I>&gt;<i>
</I>&gt;<i>
</I>&gt;<i> Regards,
</I>&gt;<i>
</I>&gt;<i> Buchan
</I>&gt;<i>
</I>
-- 
LinuxCabal Asociaci&#243;n Civil
Ing. Richard Couture
Novell CNE, ECNE, MCNE
HP/Compaq ASE
Tel.: (+52) (333) 145-2638
Cel.: (+52) (044) 333 377-7505
Cel.: (+52) (044) 333 377-7506
Web: <A HREF="http://www.LinuxCabal.org">http://www.LinuxCabal.org</A>
E-Mail: <A HREF="https://www.mageia.org/mailman/listinfo/mageia-dev">rrc at linuxcabal.org</A>
Hosted en la nube Cloud Sigma - www.CloudSigma.com

AVISO DE CONFIDENCIALIDAD: Este correo electr&#243;nico, incluyendo en su 
caso, los archivos adjuntos al mismo, pueden contener informaci&#243;n de 
car&#225;cter confidencial y/o privilegiada, y se env&#237;an a la atenci&#243;n &#250;nica 
y exclusivamente de la persona y/o entidad a quien va dirigido. La 
copia, revisi&#243;n, uso, revelaci&#243;n y/o distribuci&#243;n de dicha informaci&#243;n 
confidencial sin la autorizaci&#243;n por escrito de LinuxCabal est&#225; 
prohibida. Si usted no es el destinatario a quien se dirige el presente 
correo, favor de contactar al remitente respondiendo al presente correo 
y eliminar el correo original incluyendo sus archivos, as&#237; como 
cualesquiera copia del mismo. Mediante la recepci&#243;n del presente correo 
usted reconoce y acepta que en caso de incumplimiento de su parte y/o de 
sus representantes a los t&#233;rminos antes mencionados, LinuxCabal tendr&#225; 
derecho a los da&#241;os y perjuicios que esto le cause.

</PRE>












<!--endarticle-->
    <HR>
    <P><UL>
        <!--threads-->
	<LI>Previous message: <A HREF="016149.html">[Mageia-dev] bug, omission or feature
</A></li>
	<LI>Next message: <A HREF="016176.html">[Mageia-dev] bug, omission or feature
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#16160">[ date ]</a>
              <a href="thread.html#16160">[ thread ]</a>
              <a href="subject.html#16160">[ subject ]</a>
              <a href="author.html#16160">[ author ]</a>
         </LI>
       </UL>

<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>