gksu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Improving gksu: lib, server, basic client


From: Allan Douglas
Subject: Re: Improving gksu: lib, server, basic client
Date: Mon, 27 Oct 2003 23:17:51 -0200

> > Imagine: You are gone, buying Passatempo. But you leaved the computer on,
> > X running, and gksud open. Your little hacker sister then sits down on
> > computer, make a fake client, and run it with _your user_. Great! She now
> > knows that your password is "ihatemysister", a good excuse for deleting
> > your home dir...
> 
> That might happen to sudo, and is much easier, I think.

No, that can't happen to sudo. Sudo doesn't keep the password, sudo doesn't 
show the password... (see my other email)


> Security
> is also on the user, so if I'm gone buying Passatempo I'll lock
> my screen before leaving. That's what I do when I get away from the
> keyboard.

I agree.

> That is not a problem with gksud at all, but with 'remember
> the password for X time'. I think it is a valid worry, but
> the solution is teaching the user.

The problem is with "keeping the plain password".

[]'s




reply via email to

[Prev in Thread] Current Thread [Next in Thread]