Subject: Re: Weekly BSD Security Digest 2000/07/10 to 2000/07/16
To: RJ Atkinson <rja@inet.org>
From: Perry E. Metzger <perry@wasabisystems.com>
List: tech-x11
Date: 07/24/2000 13:07:21
RJ Atkinson <rja@inet.org> writes:
> None the less, I think it would make a quite reasonable
> default for all *BSDs, perhaps even for XFree86 in general.
> The number of folks who want remote access is smaller than those
> who don't need it, I'd guess. In any event, I believe in systems
> that ship secure by default.
>
> If undertaken, it is important that this choice/change
> is clearly documented and that any clues needed to run an
> X server without that option were also well documented.
It would be pretty easy for a user to undo. All we'd really need to do
is ship a startx that included -nolisten tcp.
The question is how to document it in such a way that users would
actually get the documentation. I'm not really sure on that
part. Documentation of such things has traditionally been our weakest
area.
--
Perry E. Metzger perry@wasabisystems.com
--
Quality NetBSD Sales, Support & Service. http://www.wasabisystems.com/