[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#415064: kdm theme functionally inferior to kdm's default theme



Matthew McGuire a écrit :

Filipus Klutiero wrote:
Package: desktop-base
Version: 4.0.1
Severity: wishlist

desktop-base is installed by default and replaces kdm's default theme by
a theme which doesn't allow selecting the user from a list. This reminds
me a bit too much Sarge's gdm (as it is configured on my desktop, at
least).




Hi Filipus,

Although we all appreciate the user selection interface I am not
convinced that we want it running 'by default' on all desktops.

I am, definitely.

The
difficult thing here is that in some (possibly many) cases you do not
want your login screen to list the 'known' users. This alone presents a
basic security risk and could allow an intruder to use this list to
their advantage. For home users this poses no real problem, but for
networks this could be a very real problem for groups of people who
authenticate against the network. This is worse for medium to large size
businesses or schools that have a long list of users.

Medium to large size businesses and schools will find it much easier to disable the list. I have no idea what significant security risk a list of users could create - please elaborate if you want.

So as a result it
is better to err on the side of caution and not provide the list by default.
I strongly disagree.




Reply to: