[plug] Passwords and Liability

Matt Kemner zombie at wasp.net.au
Sun Jan 28 00:05:26 WST 2001


On Sun, 28 Jan 2001, The Thought Assassin wrote:

> Also, not knowing the customers' passwords can reduce liability.

How?

I don't need to know your password to impersonate you (via su(1) from
root, or via temporarily changing your password to a "known" one, and then
changing it back)

 - Matt




More information about the plug mailing list