Well, an easy way to change your password if forgotten is an extra functionality. In this case, the user will have to go through what an attacker would do: burn a Live system, reconfigure the BIOS to boot it, read GRUB's password and edit GRUB's menu. Nothing hard and that is my point: no extra security is provided (unless you encrypt the disk) given a local access to the machine. Nevertheless I understand your point: the alpha student/employee will not attempt to boot a Live system (if he/she even knows what it is!). However the alpha Trisquel's user, who lost her password, will not either...

Reply via email to