>>"Thomas" == Thomas Quinot <quinot@email.enst.fr> writes:

 Thomas> Le 2000-02-02, John Goerzen écrivait :
 >> Not at all.  Is not this already done in the docs for MBR?  I recall
 >> reading about it there...

 Thomas> There is no documentation whatsoever that, when a system is

        So whats /usr/doc/mbr/README? chopped liver? ;-)

 Thomas> installed with the default settings, then the installed MBR
 Thomas> will be the one from the package named "mbr".  There is no
 Thomas> documentation whatsoever in the installation procedure that
 Thomas> it will by default install an MBR that unconditionnally
 Thomas> allows booting from a floppy disc.

        The default is not havig a password in LILO, and the default
 always has been allwing floppy boots. In fact, that is indeed
 standard behavious, and the principle of least surprise says we do
 not change that. 

        If this is a problem, then indeed, the documentation should be
 highlighted in a Securing Debian document. 

