You’re in the front of a Linux computer, you need a root access. What do you do?
jovicailic.org
jovicailic.org
This is exactly why everybody should be using full-disk encryption. It is ridiculously easy to set it up both on OS X (with FileVault) and Linux (with a plethora of options), and even on Windows machines. There is absolutely no reason why not to do this.
Big-company encryption software cannot be trusted anymore. (If it ever could have been...)
Edited.
Anyway, want to gain access to the computer? Get a screwdriver.
That's true, but creating a root password in Ubuntu is child's play:
$ sudo passwd
(enter user password for sudo access to root privilege level)
(enter new password for root)
(re-enter new password for root)
Done.
> The default setup is to always require sudo to access root.
Yes, but this is a cosmetic distinction, not a basic one. Setting up a root password is always a few keystrokes away.
My point? Ubuntu isn't really different from other distros in this respect, it only appears to be.
http://www.breaknenter.org/projects/inception/
Yes, that is actual working technology.
Just put glue in the firewire connector, you say? Well, for instance most laptops that can be docked are firewire-accessible through the docking port. The firewire interface is also reachable through a USB adapter. So you'd have to glue the USB ports shut as well. (Impractical). Even if you do all this, most motherboards have the FireWire interface enabled on a PCI level, even if there are no physical PCI ports on the computer. So against this attack you'd be pretty much hosed regardless, unless you use a chipset that explicitly doesn't implement FireWire.
Also, FireWire over USB is repeatedly mentioned as not working.
I probably own the machine. If the data on the storage is not encrypted, I own that too.
If I don't want to disassemble anything, I just plug in a liveUSB and it's all mine.
If the BIOS has USB/CD boot disabled? I pull the CMOS battery.
If that fails? The google probably knows the BIOS reset sequence for your board and soon so will I.
=======================================================================
Physical security is important too and FDE is not optional. [Even if you have nothing to hide]
If properly secured, physical hacking is not as easy as it used to be.
This is what we did to a number of machines at this year's SouthWest CCDC we were provided no login information for.
Or did we need to get root access to the previous running OS? Be more specific in that case ;)