[2141] in Kerberos
Re: New User Accounts
daemon@ATHENA.MIT.EDU (George Michaelson)
Wed Sep 2 00:35:44 1992
Date: Wed, 2 Sep 1992 04:16:55 GMT
From: ggm@brolga.cc.uq.oz.au (George Michaelson)
To: kerberos@shelby.Stanford.EDU
smb@ulysses.att.com writes:
>Put a ``passwd'' command in the initial .profile, and arrange for the
>real default .profile (or .login if your religion runs that way) to
>be installed by the initial version.
We were hacked from an account created but never legally used within
the non-expiry period. The initial password was admittedly insecure.
Yes... the first command traced on the hacked account was to change the
password.
I now believe that in some circumstances you need to actually stand over
the customer and MAKE them initialize the password to a secure value.
-George
--
George Michaelson
G.Michaelson@cc.uq.oz.au The Prentice Centre | There's no market for
University of Queensland | hippos in Philadelphia
Phone: +61 7 365 4079 QLD Australia 4072 | -Bertold Brecht