Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Buzzword Bonanza
Elias Levy, SecurityFocus 2000-05-01

Security companies can make headlines by using the right jargon, even when it's wrong.

Comments Mode:
A couple of comments 2000-05-01
Anonymous (3 replies)
Re: A couple of comments 2000-05-01
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Re: A couple of comments 2000-05-01
Anonymous (1 replies)
Re: A couple of comments 2000-05-01
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (3 replies)
Re: A couple of comments 2000-05-02
Anonymous (1 replies)
Re: A couple of comments 2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>
Re: A couple of comments 2000-05-02
Anonymous (2 replies)
Re: A couple of comments 2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Re: A couple of comments 2000-05-02
Anonymous (1 replies)
Re: A couple of comments 2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>
Re: A definition from an observer 2000-05-03
Anonymous (1 replies)
Re: A definition from an observer 2000-05-05
Anonymous


The Jargon file definition seems very right. A back-door is a way in that is not suspected by the owner, regardless of motivation.

I have written a number of web administration packages. And even though I am not super-security conscious, I have them all programmed so that the package *will not work* until you change the root password. That's right, until you change the password you can only do one thing: change the password (and no matter what you do you get taken to a screen that says, prior to customizing this program you must change the password).

IMHO all packages should have this feature.

The RH package seems to go beyond not offering this security feature -- IIUC it actually takes away from it by (falsely) telling the user no such password exists. If that's not a back-door, I don't know what is!!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/25/1694#1694
Re: A couple of comments 2000-05-02
Anonymous (1 replies)
Re: A couple of comments 2000-05-03
Anonymous
A couple of comments 2000-05-02
Matthew Pemble <matthew (at) idrach (dot) com [email concealed]>
A couple of comments 2000-05-05
Anonymous
Glad to see this... 2000-05-01
Anonymous
Simple solution. 2000-05-04
Anonymous
Not back door by Def. used 2000-05-05
Anonymous
Microsoft did the same at Win2K 2000-05-05
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus