[2316] in Kerberos
Re: kerberizing xlock
daemon@ATHENA.MIT.EDU (Jim Haynes)
Thu Oct 29 18:33:39 1992
From: haynes@cats.UCSC.EDU (Jim Haynes)
Date: Thu, 29 Oct 92 10:05:19 -0800
To: kerberos@Athena.MIT.EDU
Some versions of Kerberized login edit the user's encrypted password into
the /etc/passwd file. In such cases the existing xlock will work because
there is a password to get from the local password file. We have found
this feature of login to be undesirable on multi-user machines because
it exposes a number of encrypted passwords to guessing attacks.