[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: mingetty allows control c



Ethan Benson writes:

> should mingetty allow control C to work?
>   the delay may be cancelled this way which some would consider a 
> security problem..

IMHO it's fine. You can't exactly brute force a password if you have
to actually do the typing on a keyboard, and mingetty only works on
the console. For example, with xdm there's no delay at all. It's
telnet sessions and modem gettys that we have to worry about, because
that's where you can set up expect or somesuch to type the passwords
in for you.

If I'm totally off base, someone please correct me, because I always
go and cut the delay time in /etc/login.defs from 3 seconds to 1.

> you can also disable for 5 minutes by holding down control C which 
> causes mingetty to respawn to fast for init's taste.

That happens with anything, regular getty included.

-- 
Written with 100% free software. Please support the following websites:
www.noamazon.com www.eviltoy.com www.debian.org www.gnu.org lpf.ai.mit.edu


Reply to: