On Fri, Apr 21, 2006 at 05:18:34PM +1000, Simon Wong wrote:
> On Fri, 2006-04-21 at 17:11 +1000, Matthew Hannigan wrote:
> > As I don't think anyone is actually able to decrypt
> > to get root's password, the only way is social engineering.
> 
> I am 99.9% sure but I'm still very cautious.
> 
> > And when the prize of a $1000 is worth many months average wages
> > in some places...
> > 
> > You can imagine someone bribing with hald the prize money
                                           ^half
> > or using it to setup blackmail or whatever ...
> 
> Someone already did on the Ubuntu-AU list :-)
> 
> I can assure you that my rep (and future business) is worth more than
> that and I am the only one who knows it as well as the contents of the
> file :-)
> 
> Blackmail starts becoming illegal and a matter for the police so we're
> probably safe there...I hope!

When are you going to set the root password?  Are you sure
no-one is going to put a key-logger on the keyboard cable?
A camera over your shoulder?  Trojan /bin/login to mail/store
the cleartext?

These things have a habit of going pear-shaped, but good luck!

Matt

-- 
SLUG - Sydney Linux User's Group Mailing List - http://slug.org.au/
Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html

Reply via email to