Great Circle Associates List-Managers
(February 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Poll/Voting Facility (fwd)
From: marilyn @ deliberate . com (Marilyn Davis)
Date: Tue, 10 Feb 1998 22:45:56 -0800 (PST)
To: aaron+lm @ schrab . com (Aaron Schrab)
Cc: marilyn @ deliberate . com, list-managers @ greatcircle . com, development @ deliberate . com
In-reply-to: <19980211003259.52495@fnord.guru.execpc.com> from "Aaron Schrab" at Feb 11, 98 00:32:59 am


Thanks again Aaron,

Norbert Bollow taught us about the '*' in the encrypted password field
of the password file producing a new user that only root can access.
This is just what we need and solves all arguments.  There is no
reason to chose a priority.

I really can't blame us too much for not knowing this tidbit.  Our man
pages don't mention it that I can find.  I found it in one book of man
pages but it was very poorly documented and didn't say exactly what it
is.

Is part of Linux security *not* to document such an excellent security
feature?  :^)

But we've tested it and we're on the road to better security.  So
thanks everyone for pointing out our error.  

BTW, if Norbert were to report the security bug to
bugs@deliberate.com, I'd snail-mail him tickets to a party on Dec 31,
1999.

                                       *
Marilyn                               *
                                     *
                                    *
Marilyn Davis, Ph.D.-------------- * ---- eVote - online polling 
|                                 *       software for email lists:
3790 El Camino Real, #147  *     *        eVote-info@deliberate.com 
Palo Alto, CA 94306 USA     *   *         
(650) 493-3631 ------------- * * -------- marilyn@deliberate.com -------
                              *           http://www.deliberate.com




Follow-Ups:
References:
Indexed By Date Previous: Re: Poll/Voting Facility (fwd)
From: Aaron Schrab <aaron+lm@schrab.com>
Next: Re: Poll/Voting Facility (fwd)
From: "Nathan J. Mehl" <nmehl@leftbank.com>
Indexed By Thread Previous: Re: Poll/Voting Facility (fwd)
From: Aaron Schrab <aaron+lm@schrab.com>
Next: Re: Poll/Voting Facility (fwd)
From: "Nathan J. Mehl" <nmehl@leftbank.com>

Google
 
Search Internet Search www.greatcircle.com