Subject: Re: solving various bug reports...
To: None <tech-security@NetBSD.ORG>
From: der Mouse <mouse@Rodents.Montreal.QC.CA>
List: tech-security
Date: 06/26/1997 15:04:06
>>> what's wrong with just moving inetd to the very end of rc, right
>>> before it prints the date?
>> you still have a race condition.
>> securelevel doesn't change until after init is done with rc.
> that's very true, but you're only talking about a fraction of a
> second. that's not even long enough for you to log in locally via
> 100base-t and do *anything*.
Not long enough for me-the-human to. Quite possibly long enough for a
computer, acting on my behalf, to. I'm certainly not about to bet the
security of my system that it's too short to hit.
Not that this is a reason not to move inetd's startup line. Just that
we shouldn't move it and proceed to consider the problem thereby
eliminated - moving it is cheap and easy and shrinks the window, which
is an improvement even though it isn't a cure.
der Mouse
mouse@rodents.montreal.qc.ca
7D C8 61 52 5D E7 2D 39 4E F1 31 3E E8 B3 27 4B