On Tue, Nov 05, 2019 at 07:42:06AM +0000, john heasley wrote:
>    In addition,the "factory-reset" RPC might also be used
>    to trigger some other restoring and resetting tasks such as files
>    cleanup, restarting the node or some of the software processes,
>    setting some security data/passwords to the default value, removing
>    logs, or removing any temporary data (from datastore or elsewhere),
>    etc.
> 
> It seems that this should all be part of this draft.  An operation that
> wipes a device for decommission is useful.  Whether it is a home or
> commercial device.

Yes to your point.

But every time I read the phrase "setting some security data/passwords
to the default value" I am feeling uneasy. The notion of 'default
passwords' is scary and a knob to restore default passwords even more
so. Perhaps the text should say instead 'removing security credentials
and restoring default security settings'.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
Fax:   +49 421 200 3103         <https://www.jacobs-university.de/>

_______________________________________________
netmod mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/netmod

Reply via email to