[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Single-use root account?



On Fri, 2003-11-07 at 07:55, J. Bruce Fields wrote:
> On Fri, Nov 07, 2003 at 02:58:48AM -0600, Alex Malinovich wrote:
> > I've decided that it's about time I look for a solution to a problem
> > that's been bugging me. On certain occasions, I find it necessary to
> > have one of my roommates do something to the network at home when I'm
> > not there. As such, they generally will need root access to do it. While
> > I certainly trust them, I'm very security conscious and wouldn't feel
> > comfortable giving them my root password.
> 
> Why not?  They already have physical access to the machine, what more
> would you give up to them by telling them the root password?  For a home
> computer, I don't see much reason not to just stick the root password on
> a post-it note on the monitor.... You already trust anyone that's in a
> position to see it.

99% of the people who come by my apartment don't know enough to do any
of that. The 1% who do, only really know how to use Windows and have
never touched a CLI in their lives.

In regards to the roommates at least, they both use Debian and know
enough about it to do some basic functions from a terminal. As such, I
could tell them what to do over the phone without having to hold their
hands through the whole procedure. The reason I'm so concerned about the
one-time-use password is not to defend against any maliciousness on
their part, but rather to defend against stupidity on their part. (Or to
cover up my stupidity by having them fix something I broke before I get
home. :)
-- 
Alex Malinovich
Support Free Software, delete your Windows partition TODAY!
Encrypted mail preferred. You can get my public key from any of the
pgp.net keyservers. Key ID: A6D24837

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: