Re: Passwordless root access
- From: stan@xxxxxxxxxxxxxxxxxx
- Date: Wed, 8 Feb 2006 20:24:39 +0000 (UTC)
CWO4 Dave Mann <misterfixit@xxxxxxxxxxxx> wrote:
: that eliminates the possibility of loading something from an external
: device. Second, don't build the box with capability for a user to shut the
: system down or even get out of the gui environment. Third, remove the
That would of course include removing any ability to cycle the
power.
: possibility of command line invoke of applications.
You forgot-- remove the ability to invoke applications from the network
via a browser. Or realistically- remove the ability to invoke
_any_ applications or any kind by any means other than the limited set
that you provide. Obviously this would mean no JAVA ability or the like.
: I do not know how difficult building that kind of box would be ... I think
: that it would be easier to build your own kernel with those security
: factors in place and then burn the OS to a ROM and embed the system in
: hardware.
Indeed. That's what embedded systems are all about. Throwing a general
purpose computer out in a kiosk or the like is NEVER going to be secure.
You need something with vastly more limited configurability/usability
and almost certainly no ability to boot from anything other than read-only
media.
And of course as everyone else has said-- forget about software
until you have physical security in place. Internet cafes with their
OTS PC's sitting there are not what one would call secure.
Stan
--
Stan Bischof ("stan" at the below domain)
www.worldbadminton.com
.
- Follow-Ups:
- Re: Passwordless root access
- From: CWO4 Dave Mann
- Re: Passwordless root access
- References:
- Passwordless root access
- From: rstamps@xxxxxxxxx
- Re: Passwordless root access
- From: Jeremiah DeWitt Weiner
- Re: Passwordless root access
- From: rstamps@xxxxxxxxx
- Re: Passwordless root access
- From: CWO4 Dave Mann
- Passwordless root access
- Prev by Date: Re: Passwordless root access
- Next by Date: Re: Passwordless root access
- Previous by thread: Re: Passwordless root access
- Next by thread: Re: Passwordless root access
- Index(es):
Relevant Pages
|