Re: How do you stop !root logins from dialup connections (fwd)

Robert Hanson (roberth@cet.cet.com)
Fri, 29 Sep 1995 16:40:01 -0700 (PDT)

so what you are saying is that, there are enough buttheads out there that
wanna probe my portmaster hard enough to find that !root is disabled and that

#R@oo-T! is my admin pm login and then try for a password on that once
they discover that?

-rh

On Sat, 30 Sep 1995, Per Hedeland wrote:

> >From: Robert Hanson <roberth@cet.cet.com>
>
> >i said programable LOGIN name... other than "!root".... "if" they dont know
> >what to logon as then hey... your home free... password are supplemental
> >and "of course" necessary after the fact of initiating a login...
>
> Yes, I understood that. What I'm saying is that from a security
> viewpoint, a variable userid of length m + a variable password of length
> n is (at best) equivalent to a fixed userid + a variable password of
> length m + n. I.e. you've effectively made the userid part of the
> password.
>
> But anyway, I've certainly never argued for the *removal of the
> possibility* of !root logins on the serial ports, just a *way to
> disable* them for those who wish/need to. I can't really see why anyone
> would object to this - except Livingston who would have to implement it,
> of course.:-)
>
> --Per Hedeland
> per@erix.ericsson.se
>