Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: Creation of User profiles at install: msg#00138

Subject: Re: Creation of User profiles at install
On Mon, Oct 30, 2006 at 06:58:03AM -0400, frank claessen wrote:

> Edubuntu asks for one user only and that is an administrative user. For
> security reasons I don;t think this is a good idea.

Why not?  How is this inherently less secure than a root account?

By creating an initial priveleged user, that executes commands via the
sudo command, you have better, fined grain control.  For starters,
anything issued via the sudo command is logged.  Not so for a root
login.  As well, it more directly ties admin privs to a real userid, as
opposed to the nebulous "root" account.  In addition to this, every
external hacker knows that any unix-like box has a "root" account, and
so, it's frequently the subject of brute-force password attacks.
Leaving this account disabled by default eliminates this worry.

There's an entire wiki page documenting all these reasons, at the Ubuntu
site.  You might want to check it out.

> Later on you can
> change the password for the root account while being logged an as the
> user that was created during installation ?!?!!!!

Sure, it's still Linux, and there's nothing to stop a knowlegeble admin
who's used to the old idea of an enabled root account from simply adding
the password.  The idea here is to *ship the OS in a default secure
state*.  There's nothing stopping me from creating users with empty
passwords either.  Or enabling writable anonymous FTP sites.  Or
installing the old rsh style commands.  Nothing *STOPS* you from making
your system *LESS* secure.  That's the admin's choice.

> Unbelievable!!

How so?

> Would like to know what others think about this. I would prefer the way
> of the other distro's

The key phrase in your email is "..other distros...".  Other distros do
it the traditional way.  Ubuntu is doing something new, which has been
proven to be no *less* secure than the old way, and certainly, one
command post install (sudo passwd root) gets you "the old way" that you
seem to like.  Seems like an easy solution to me.

Scott

-- 
Scott L. Balneaves | "Looking beyond the embers of bridges glowing behind us
Systems Department |  To a glimpse of how green it was on the other side..."
Legal Aid Manitoba |    -- Pink Floyd "High Hopes"



<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
user-groups.jax...    php.zend.framew...    os.solaris.open...    web.quixote.use...    java.openjdk.ho...    ietf.secmech/20...    gnu.glpk/2004-0...    recreation.cars...    network.smokepi...    linux.drivers.i...    cms.opencms.dev...    fonts.gfontview...    text.xml.soap.u...    voip.nist-sip/2...    debian.ports.hp...    xfree86.interna...    science.biology...    qnx.openqnx.dev...    mail.sylpheed.c...    busybox/bios/20...    emulators.kvm.s...    hardware.openco...    apple.fink.begi...    kde.german/2006...   
Home | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation