LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-27-2008, 11:18 AM   #1
darthaxul
Member
 
Registered: Aug 2008
Distribution: Devuan; Gentoo; FreeBSD
Posts: 236

Rep: Reputation: 19
passwords on installs


I got 5 diffrent OS's on one system and 5 different passwords for them. I've been using different passwords on separate OS installs for the same system. I dont think it makes it any more secure though so I think im going to go with one password per user, no matter what OS booted into.
 
Old 12-27-2008, 03:59 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by darthaxul View Post
I got 5 diffrent OS's on one system and 5 different passwords for them. I've been using different passwords on separate OS installs for the same system. I dont think it makes it any more secure though so I think im going to go with one password per user, no matter what OS booted into.
Ummm, okay. So what's your question?
 
Old 01-03-2009, 05:57 AM   #3
chakkerz
Member
 
Registered: Dec 2002
Location: Brisbane, Australia
Distribution: a few...
Posts: 654

Rep: Reputation: 32
1) no, odds are its no more secure because depending on the OS's they may be able to see the different OS's partitions (even if you don't mount them). This is assuming multi-boot, not VMs.

2) That said, who do you anticipate will compromise your security seeing as you either are multibooting - in which case unless you use LDAP to manage your users you're in for fun times keeping things synchronized and odds are this will only be for you, so really it makes no difference. Alternatively, you're doing VMs. in which case having 5 different root passwords is probably sensible.

I say "probably" because if you're maintaining five different OSs and are having users connect to them remotely, and you don't know about the security implications that may arise from those choices, odds are you have other gaping holes.

3) One password per user, per OS, is rather unmaintainable in the real world. If this is just for you, but the systems are online (again VMs) then odds are you'll be compromised for other reasons. See point 2. If this is for a host of users, and they can ssh to your hosts, you won't be able to enforce password skews efficiently anyway. Nevermind that you'll never get anything done seeing as your clients will constantly be calling you because they're confused, or because someone hacked an account because a client wrote his/her passwords down (so they wouldn't get confused).

4) Summary: complex systems are generally less secure than simple ones. Use individual root passwords per hosts, use alike passwords per user per groupable service (eg one password for Linux, one for FreeBSD and one for Windows; or one for webservers, one for database servers and one for fileservers) but keep in mind that at the end of the day you have little control as to what your users will do.

Last edited by chakkerz; 01-03-2009 at 06:01 AM. Reason: typographical fixes, minor clarifications
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to convert user passwords and group passwords using pwconv? dolceinter1 Linux - Security 2 11-04-2008 10:03 PM
updating samba passwords with system passwords paranoid times Linux - Software 3 10-03-2006 09:04 PM
Sync MySQL passwords with local account passwords? turbine216 Linux - Software 2 02-18-2005 03:15 AM
Completely uninstalling MySQL and its passwords passwords...how? I locked myself out! Baix Linux - Newbie 2 01-30-2005 04:10 PM
Is there a way to sync Samba passwords with linux user passwords MarleyGPN Linux - Networking 2 09-09-2003 10:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration