[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[no subject]
- <!--x-content-type: text/plain -->
- <!--x-date: Thu May 19 15:59:25 2005 -->
- <!--x-from-r13: wevpxzna ng tznvy.pbz (Xbanguna Dvpxzna) -->
- <!--x-message-id: [email protected] -->
- <!--x-reference: [email protected] -->
- <!--x-reference: [email protected] -->
- <!--x-reference: [email protected] -->
- <!--x-reference: [email protected] --> "http://www.w3.org/TR/html4/loose.dtd">
- <!--x-subject: [ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE -->
- <li><em>date</em>: Thu May 19 15:59:25 2005</li>
- <li><em>from</em>: jrickman at gmail.com (Jonathan Rickman)</li>
- <li><em>in-reply-to</em>: <<a href="msg00670.html">[email protected]</a>></li>
- <li><em>references</em>: <<a href="msg00525.html">[email protected]</a>> <<a href="msg00651.html">[email protected]</a>> <<a href="msg00662.html">[email protected]</a>> <<a href="msg00670.html">[email protected]</a>></li>
- <li><em>subject</em>: [ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</li>
> I am not putting myself out to be that knowledgable. I hire people that are.
> Moreover, you are not willing to go to the extent (that I am) to prove YOUR
> box is secure. If your box is secure, you will be able to substitute YOUR BOX
> for mine in the challenge (using the same rules I have set forth).
You are "putting yourself out" to be a friggin' idiot, to be blunt about it.
Protecting the root account and it's associated privileges is about
85% of the goal of Unix (and consequently Linux) security best
practices. By offering up the root account right off the bat, you have
failed to prove anything other than that you have (or at least believe
you have) a sound backup and recovery plan. The minute you give out
the root password you have, by default, failed any reasonable test of
security. Now for the sake of discussion, and keeping Jimpop from
pointing out how ignorant I am for not factoring that in, I am taking
for granted that you do not have SELinux or some other modification to
the standard security architecture in place. Barring that, when you
give out the root password and permit a remote user to log in you have
just given up all system security for the duration of the session.
This apparently is very clear to you since you have stipulated that
you will remove all personal information from the machine prior to the
disclosure of the password. The fact that you can restore a backup is
irrelevant. I can restore a backup too. This is not a revolutionary
concept.
You seem to be redefining terms to suit your purposes. Security means
what it means, not what you choose it to mean. I'll point you to this
wiki entry for a pretty clear definition:
<a rel="nofollow" href="http://en.wikipedia.org/wiki/Security_">http://en.wikipedia.org/wiki/Security_</a>(computers)
Now, continue with your diatribe...it is proving to be a great source
of entertainment for myself and my colleagues.
--
Jonathan
</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<ul><li><strong>Follow-Ups</strong>:
<ul>
<li><strong><a name="00694" href="msg00694.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
<ul><li><em>From:</em> groups at changinglinks.com (ChangingLINKS.com)</li></ul></li>
</ul></li></ul>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00525" href="msg00525.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
<ul><li><em>From:</em> groups at ChangingLINKS.com (ChangingLINKS.com)</li></ul></li>
<li><strong><a name="00651" href="msg00651.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
<ul><li><em>From:</em> groups at changinglinks.com (ChangingLINKS.com)</li></ul></li>
<li><strong><a name="00662" href="msg00662.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
<ul><li><em>From:</em> fd0man at gmail.com (Michael B. Trausch)</li></ul></li>
<li><strong><a name="00670" href="msg00670.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
<ul><li><em>From:</em> groups at changinglinks.com (ChangingLINKS.com)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00681.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00683.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00670.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00694.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00682"><strong>Date</strong></a></li>
<li><a href="threads.html#00682"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>