[Discuss] Dropping obsolete commands (Linux Pocket Guide)
Bill Ricker
bill.n1vux at gmail.com
Wed Nov 18 13:12:30 EST 2015
On Wed, Nov 18, 2015 at 11:37 AM, Chuck Anderson <cra at wpi.edu> wrote:
> Those two options don't work for a regular user to change their own
> Full Name.
>
In IT environments, even folks in Wheel shouldn't be editing their Full
Name, that's reserved for some security application.
On a family laptop, anyone who isn't allowed to run Update won't be
changing their name either.
Maybe in a College environment you don't need to prevent a user from
changing their name without review, but the social engineering
possibilities of changing FullName of <cra at wpi.edu> to "Vice Chancellor C.
Adams" are such that i'd discourage allowing setuid chfn to contain any
breaches.
--
Bill Ricker
bill.n1vux at gmail.com
https://www.linkedin.com/in/n1vux
More information about the Discuss
mailing list