[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [POSSIBLE GRAVE SECURITY HOLD]



Le 2000-02-02, John Goerzen écrivait :

> That said, there are things that you can do to make it more secure in

True.

> said, you'll need to tie down LILO by giving it a password.  You'll
> need to padlock shut your computer's cases.  You'll need to disable
> the floppies entirely or at least disable booting from them.  You'll
> need to password-protect your BIOS.

We already do all of these.

> You may need to remove MBR.

And here is the problem:
  The MBR used by Debian by default allows any user to boot from
  floppy. No other PC MBR does that. This behaviour is documented
  nowhere.

One possible solution to the problem as we resent it is mere documentation.
Do you find it an inacceptable burden for users to BE INFORMED that
the default setup will unconditionnally allow booting from a floppy
disk?

> DEFAULT is not in anyone's best interest.  Note that even Sun machines
> can easily be halted and the BIOS entered -- at runtime -- by anyone
> sitting at the keyboard.

Anyone sitting at they keyboard who possesses the PROM password.

Thomas.


Reply to: