From owner-freebsd-security Fri Nov 9 7:29:35 2001 Delivered-To: freebsd-security@freebsd.org Received: from proxy.centtech.com (moat.centtech.com [206.196.95.10]) by hub.freebsd.org (Postfix) with ESMTP id AE2A037B41A for ; Fri, 9 Nov 2001 07:29:31 -0800 (PST) Received: from sprint.centtech.com (sprint.centtech.com [10.177.173.31]) by proxy.centtech.com (8.11.6/8.11.6) with ESMTP id fA9FTU408846 for ; Fri, 9 Nov 2001 09:29:30 -0600 (CST) Received: from centtech.com (proton [10.177.173.77]) by sprint.centtech.com (8.9.3+Sun/8.9.3) with ESMTP id JAA22564 for ; Fri, 9 Nov 2001 09:29:30 -0600 (CST) Message-ID: <3BEBF636.7AF24D99@centtech.com> Date: Fri, 09 Nov 2001 09:28:54 -0600 From: Eric Anderson Reply-To: anderson@centtech.com Organization: Centaur Technology X-Mailer: Mozilla 4.78 [en] (X11; U; Linux 2.2.12 i386) X-Accept-Language: en MIME-Version: 1.0 To: freebsd-security@freebsd.org Subject: Re: reboot,ctrl+alt+del,shutdown References: <20011109101749.E7523-100000@mohegan.mohawk.net> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Stop the madness! :) I think it's been drilled into the ground now.. > > > 1. Its answered in the FAQ > > Agreed, and the querant should have been directed there. > > > 2. Disabling cntrl+alt+del wont stop any malicious user. It will only > > stop accidents from happening. > > I disagree. If the reset button and the power switch have been disabled > and the power cord is not accessible and/or the machine is locked in a > cabinet (but the keyboard is not), then disabling ctrl-alt-del could well > prevent malicious rebooting, especially if the malicious one is a casual > miscreant rather than a "pro". This applies in particular for paranoid > installations where it is likely a policy matter. > > Ergo, this is a security question, at least in my mind. However, it is > addressed in the faq and the querant should have been directed there. > -- ------------------------------------------------------------- Eric Anderson anderson@centtech.com Centaur Technology No single raindrop believes it is to blame for the flood. ------------------------------------------------------------- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message