BSD tty security, part 3: How to Fix It

99700000 haynes at felix.ucsc.edu
Mon Apr 29 15:30:03 AEST 1991


In article <564 at appserv.Eng.Sun.COM> lm at slovax.Eng.Sun.COM (Larry McVoy) writes:
>
>Is all this fuss really worth it?  I hate to appear caveliar and I
>don't speak for Sun, just as a user, but does anyone really care?  OK,
>anyone except the Feds?  Yeah, the system is insecure.  In many
>places.  It seems to me that worrying about anti-social behavior
>through tty's is the least of our problems.

I think it depends a lot on the situation where the system is used.
In a business environment you care a lot about keeping out unauthorized
people; but you can expect the authorized users to be well-behaved
toward one another.  In the academic environment we don't worry so much
about keeping out unauthorized users - we have thousands of legitimate
users, and we can be sure some of them are going to give out their
passwords to others.  But we have lots of naive users, and some mischievous
users, and some malicious users, and some sets of feuding users; and
we would rather have the system do what it can to protect them rather
than have them all come crying to the management about the abuse they are
getting at the hands of other users.  Even in the business world
you may need to worry about harassment and unauthorized access by
authorized users.



More information about the Comp.unix.wizards mailing list