Security Basics mailing list archives

Re: Windows 98 box is 'owned'


From: dante hicks <dante () wiw org>
Date: Mon, 4 Oct 2004 02:56:28 -0400


I am going to install a kde desktop for her, including a passwordless
automatic login using KDM (physical security of her box is not important),
tweak a few settings so it looks familiar and everything is where she
expects it. This just seems the best way to go because, as mentioned, at
least I could help her if she had problems.

i might be missing something, but that would be almost identical to putting a 
patchless windows 98 box directly on the internet.  either disable *every* 
service (httpd,rpc,etcetc), or don't consider that option. surely she can 
handle a single password (or two, root + unpriv user)?  then have her unpriv 
user store all the passwords she might ever need (email, ebay, whatever) 
through the client.

zero intervention needed, and still secure.  


Current thread: