[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] ROOT



Cobalt really really need to give the admin user (or indeed anyone with physical access) the ability to boot into single user mode.
 
You can restore the OS from CD, surely they could modify the boot block to allow single user mode to work. For a sys admin with physical access to the machine, and indeed another networked machine for the cd this is a very important feature. Having a password reset option hardwired into the raq itself is nice ... BUT
 
I have encountered a situation presently where the passwd reset does NOT work. Think about the implications of that.. once security is compromised (that is, if the system needs a push to fall over)you are faced with an entire restore of all your data and OS should you be able to recover it.
 
This saddens me, otherwise the Cobalt is a great product but I do not beleive I will be buying any more unless I can be assured this wont happen again.
 
just for the record.. its happened twice in three months on a Raq2. I also dont beleive either occurance has anything to do with security being compromised. THIS IS A BUG.