#7443 HIGH 8.2.0 (: Configuration tasks requiring root authority.

Zarro Boogs per Child bugtracker at laptop.org
Mon Jul 7 19:42:31 EDT 2008


#7443: Configuration tasks requiring root authority.
------------------------+---------------------------------------------------
   Reporter:  mstone    |       Owner:  erikos              
       Type:  defect    |      Status:  new                 
   Priority:  high      |   Milestone:  8.2.0 (was Update.2)
  Component:  distro    |     Version:                      
 Resolution:            |    Keywords:  8.2.0:?             
Next_action:  diagnose  |    Verified:  0                   
  Blockedby:            |    Blocking:                      
------------------------+---------------------------------------------------
Changes (by mikus):

 * cc: mikus at bga.com (added)


Comment:

 I believe there are TWO levels of "protection" possible.  Personally, I
 prefer the first:

 (1) Give root a password.  Then ordinary Activities ought to not be able
 to achieve root authority without the user supplying the password.  Note
 that this is how the ship-2 and olpc-3 builds worked -- it is only the
 recent Update.1 and Joyride builds which permit getting into root without
 supplying the password, even when root *does* have a password.

 (2) Deactivate all existing mechanisms of getting into root.  The
 principal one is the text console (ctl-alt-F1 / ctl-alt-F2).  In addition,
 get rid of 'sudo' and the gratuituous "root icon" in Terminal.

-- 
Ticket URL: <http://dev.laptop.org/ticket/7443#comment:1>
One Laptop Per Child <http://laptop.org/>
OLPC bug tracking system


More information about the Bugs mailing list