Hello hackers...

I'm wondering why there is "insecure" options in /etc/ttys for virtual
consoles.
As we all know, "insecure" for ttyvX means that we can't directly log in
as root, but "insecure" for console field in /etc/ttys means only that
we will be asked  for root's password in single mode.
Hmm, if I got psyhical access to machine and ttyvX are in "insecure" mode
and I know root's password I can just reboot machine and log in as root.
So if "insecure" mode is a security feature, shouldn't this be in that
way (in single mode):

Login: <wheel group member>
Password: <wheel group member's password>
Root's password: <root's password>

?

-- 
Pawel Jakub Dawidek
UNIX Systems Administrator
http://garage.freebsd.pl
Am I Evil? Yes, I Am.

To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-hackers" in the body of the message

Reply via email to