+1 2012/5/28 Yamaban <foerster@lisas.de>:
On Mon, 28 May 2012 13:45, Bruno Friedmann <bruno@...> wrote:
By default the userlist is shown in kdm. Several time ago security team would like to see it removed.
It was the case mainly due to "broken/non feature" in the previous themes used in 12.1. Now under 12.2 the new theme proposed is fully aware of userlist/domain remote login etc.
But to comply with what security team want then it seems we should have a patch changing the default show userlist to no in /usr/share/kde4/config/kdm/kdmrc.
What is your opinion on that ?
Let's be honest:
- for privat / family use, the userlist is more than just 'usefull', it's needed to considered 'user-friendly'.
- for security relevant use, the ability to 'disable' the userlist is needed to be considered 'secure enough'.
MS-Windows (Vista/7 at least) give the admin the choice.
If even MS can do this, why should we cripple our users in taking away this choice?
Maybe we should give the option to decide on this during install?
That way it could be included as an option in 'auto-install' to satisfy the 'security by obsurity/hiding' users / corporate admins needs even in bigger installations.
That's my take on the 'userlist' option. Provide the possibility for the user / admin to decide whats needed.
Cheers, Yamaban.
-- To unsubscribe, e-mail: opensuse-kde+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-kde+owner@opensuse.org
-- To unsubscribe, e-mail: opensuse-kde+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-kde+owner@opensuse.org