[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4E0129FE.7050709@redhat.com>
Date: Tue, 21 Jun 2011 20:32:14 -0300
From: Flavio Leitner <fbl@...hat.com>
To: Prarit Bhargava <prarit@...hat.com>
CC: netdev@...r.kernel.org, davem@...emloft.net, agospoda@...hat.com,
nhorman@...hat.com, lwoodman@...hat.com
Subject: Re: [PATCH]: Add Network Sysrq Support
On 06/21/2011 07:26 PM, Prarit Bhargava wrote:
>> I'm thinking on a situation where we leave the systems with this enabled
>> and then an ordinary user starts pinging the network guessing the hexa to
>> cause reboots.
>>
>
> Good point Flavio, but that's *exactly* why I wrote this in single-shot
> mode. I really think the code might be a bit too risky for most people
> to deploy in production environments. It's too risky for me to let
> someone ping and ping and ping until they luckily hit the magic number
> and figure out how to bring *all* of my systems down. What are the
> chances that a lab admin is smart enough to set the password to
> different numbers across different machines in a single lab?
I see your point. I liked the patch because of the simplicity but
oh well, if we care that much about the security, then in the end
we will have something similar to what the xt_SYSRQ does already.
fbl
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists