Subject: Re: solving various bug reports...
To: None <tech-security@NetBSD.ORG>
From: der Mouse <mouse@Rodents.Montreal.QC.CA>
List: tech-security
Date: 06/26/1997 15:04:06
>>> what's wrong with just moving inetd to the very end of rc, right
>>> before it prints the date?

>> you still have a race condition.
>> securelevel doesn't change until after init is done with rc.

> that's very true, but you're only talking about a fraction of a
> second.  that's not even long enough for you to log in locally via
> 100base-t and do *anything*.

Not long enough for me-the-human to.  Quite possibly long enough for a
computer, acting on my behalf, to.  I'm certainly not about to bet the
security of my system that it's too short to hit.

Not that this is a reason not to move inetd's startup line.  Just that
we shouldn't move it and proceed to consider the problem thereby
eliminated - moving it is cheap and easy and shrinks the window, which
is an improvement even though it isn't a cure.

					der Mouse

			       mouse@rodents.montreal.qc.ca
		     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B