Re: pam_console for debian

2002-08-22 Thread Russell Coker
On Thu, 22 Aug 2002 21:46, Sam Clegg wrote:
> On Thu, Jul 25, 2002 at 10:23:09AM -0700, David Caldwell wrote:
> > Sounds like what you really want is a way to take exclusive access to the
> > camera device somehow. Can you exclusively open the device and prevent
> > others from opening it too? I suppose even that would have a timing
> > splinter: Someone could take exclusive control before you got a chance...
>
> I would like to see someting like this for hotpluggable storage as well.
>
> If I want to keep private data (private keys etc) on a USB keyring I
> would like to be sure that nobody else can mount it before me.
>
> Perhaps the hotplug system could implement some kind of method for a
> user to say "any device plugged in the next 1 minute is mine".  Clearly
> this is vulnerable to DoS by others but this is far better than others
> being able to mount your disks/read your photos.

Ivo is apparently taking over crypto-api and hopefully he'll have it in sarge 
soon.  That should solve your problem, just encrypt the device and only the 
user with the password can get access.

-- 
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.




Re: pam_console for debian

2002-08-22 Thread Sam Clegg
On Thu, Jul 25, 2002 at 10:23:09AM -0700, David Caldwell wrote:
> Sounds like what you really want is a way to take exclusive access to the 
> camera device somehow. Can you exclusively open the device and prevent 
> others from opening it too? I suppose even that would have a timing 
> splinter: Someone could take exclusive control before you got a chance...

I would like to see someting like this for hotpluggable storage as well.

If I want to keep private data (private keys etc) on a USB keyring I
would like to be sure that nobody else can mount it before me.

Perhaps the hotplug system could implement some kind of method for a
user to say "any device plugged in the next 1 minute is mine".  Clearly
this is vulnerable to DoS by others but this is far better than others
being able to mount your disks/read your photos.

sam
-- 
sam clegg
:: [EMAIL PROTECTED]
:: http://superduper.net/ 
:: PGP :: D91EE369
$superduper: .signature,v 1.5 2002/05/17 10:23:59 samc Exp $


pgp9E4KeulXHJ.pgp
Description: PGP signature