Skip to content

ProjectDrunkenAdmin

Donald Buczek edited this page Oct 12, 2021 · 3 revisions
  • Assume worst destructive case: A person with all knowledge and credentials of current admin does its best to destroy all data
  • (not concerned with risk of stolen data in this page)
  • (only concerned with Mariux64 in this page)

Problems

  • Mariux64 systems trust each other (nfs export, unprotected ssh private keys by default for users and some privildged administrative applications)
  • Hardware of workstations and servers is accessible by an unknown number of pepple
  • lazy sysadmins (no 2FA, continuously logged in, sometimes open root shells)