[Summary] 4.0G latest patches breaks long usernames?

From: Arrigo Triulzi (arrigo@albourne.com)
Date: Thu Sep 19 2002 - 13:21:35 EDT


Dear all,

as suspected but not spoken the security fixes in the latest round of
patches closes the loophole which allowed long usernames.

A very full reply and explanation of the security hole involved (in
SIA) was sent by John Ferlan within HP Security. Earlier during the
day Harald Knipp reminded me that the Unix "standard" is 8 so I was
only lucky that I got away with it...

John also reminded me that Tru64 5.x support usernames up to 63
characters which would clearly solve my problem if only I could
upgrade (I cannot).

The solution to my problem is therefore to rename all the Windoze
boxes to names such that name$ is max. 8 characters and quietly swear
under my breath while doing so.

Arrigo

-- 
Arrigo Triulzi <arrigo@albourne.com>
Albourne Partners Ltd. - London, UK


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:48:53 EDT