From: Ed Fishel <edfishel@us.ibm.com>
> 1. Is it a security exposure to know the name of other user profiles on the
system?
> No.
> Good security design requires that even thought a user knows the name of a
> user profile, that cannot easily guess the password of the user profile or
> even know any other information about that user profile.

I agree with Ed. And everybody knows QSECOFR...
It is simply not the case that knowing a user ID is "having
won half of the battle". Still, it is also good policy not to
give away any information during the signon process.




This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2026 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.