[2141] in Kerberos

home help back first fref pref prev next nref lref last post

Re: New User Accounts

daemon@ATHENA.MIT.EDU (George Michaelson)
Wed Sep 2 00:35:44 1992

Date: Wed, 2 Sep 1992 04:16:55 GMT
From: ggm@brolga.cc.uq.oz.au (George Michaelson)
To: kerberos@shelby.Stanford.EDU

smb@ulysses.att.com writes:

>Put a ``passwd'' command in the initial .profile, and arrange for the
>real default .profile (or .login if your religion runs that way) to
>be installed by the initial version.


We were hacked from an account created but never legally used within
the non-expiry period. The initial password was admittedly insecure.

Yes... the first command traced on the hacked account was to change the
password. 

I now believe that in some circumstances you need to actually stand over
the customer and MAKE them initialize the password to a secure value.

	-George
--
                         George Michaelson
G.Michaelson@cc.uq.oz.au The Prentice Centre      | There's no  market for
                         University of Queensland | hippos in Philadelphia
Phone: +61 7 365 4079    QLD Australia 4072       |          -Bertold Brecht

home help back first fref pref prev next nref lref last post