off-topic: is a login, login?

Just a random thought.

If I seat down at a machine that says:

> Debian GNU/Linux potato portaloo tty1
> portaloo login:

How can I be sure it is the `real' login, and not just a program somebody has
run that looks like login and is supposed to capture user-ids and passwords?

First I would try ctrl+c and ctrl+z but I am sure that programs can override
both of these, so what can I do, how can I be sure?

As a sysadmin Would the solution be to run idled and chuck off idle users,
or is there another way?

