Path: utzoo!utgpu!watmath!clyde!att!osu-cis!tut.cis.ohio-state.edu!cwjcc!hal!ncoast!allbery From: allbery@ncoast.UUCP (Brandon S. Allbery) Newsgroups: news.sysadmin Subject: Re: The viral high ground--go for it while I puke in the corner Message-ID: <13163@ncoast.UUCP> Date: 22 Nov 88 03:07:08 GMT References: <16672@agate.BERKELEY.EDU> <7882@bloom-beacon.MIT.EDU> <16800@agate.BERKELEY.EDU> <161@loci.UUCP> <546@dutrun.UUCP> Reply-To: allbery@ncoast.UUCP (Brandon S. Allbery) Followup-To: news.sysadmin Organization: Cleveland Public Access UN*X, Cleveland, Oh Lines: 35 As quoted from <546@dutrun.UUCP> by hans@duttnph.UUCP (Hans Buurman): +--------------- | Mind you, we are not on the Internet yet. I can only hope that they learn | before things get serious. Your virus-of-the-month might just cause that. +--------------- About a month and a half ago, one of the sysadmins at skybridge.sdi.cwru.edu asked me for a copy of a certain program in use on ncoast which grants use of root privileges without a password. I refused, explained why, and copied the message to ncoast's Keeper of the Root Password as part of my on-going effort to get him to stop placing convenience over security. (Said Keeper claims that the program is more secure than giving out the root password to those few people who occasionally need root access. Oh, really?) Then the Internet virus broke. I hope the sysadmins of skybridge got the message reinforced by it. Ncoast's root certainly didn't; he *still* ignores me when I ask for the root access program to be dishonorably retired. I'm still waiting for some cracker to break in that way.... (Note: I never did subscribe to the "easy password" rule, and still don't; I would bet that my passwords will not be guessed by anyone, although someone may be able to decrypt it with "fdes" or etc. I make no such claim for our beloved root. Sigh. Three possible root passwords on a system is at least two too many, even if they're well-chosen.) ++Brandon -- Brandon S. Allbery, comp.sources.misc moderator and one admin of ncoast PA UN*X uunet!hal.cwru.edu!ncoast!allbery ncoast!allbery@hal.cwru.edu allberyb@skybridge.sdi.cwru.edu allbery@uunet.uu.net comp.sources.misc is moving off ncoast -- please do NOT send submissions direct Send comp.sources.misc submissions to comp-sources-misc@.