[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference bulova::decw_jan-89_to_nov-90

Title:DECWINDOWS 26-JAN-89 to 29-NOV-90
Notice:See 1639.0 for VMS V5.3 kit; 2043.0 for 5.4 IFT kit
Moderator:STAR::VATNE
Created:Mon Oct 30 1989
Last Modified:Mon Dec 31 1990
Last Successful Update:Fri Jun 06 1997
Number of topics:3726
Total number of notes:19516

269.0. "Identifying paused sessions?" by HIBOB::VANLAANEN (John VanLaanen CXO1-1/P26, dtn 522-2310) Wed Feb 22 1989 00:39

Is there any way to externally tell if a session is paused?

As we've read elsewhere, we're seeing that users prefer to pause their session
rather than quit it every night. This leaves several processes logged in over
night and no way ( that we've found ) for the system manager to tell if it is
paused or not ( i.e. security paranoia ).

The lock utility we used under VWS ( WSLOCK ) changed the name of the locking
process, so we could tell that all was ok without having to go over to that
system and look at it ( granted, this isn't foolproof security, but its at
least a help ).

Is there currently any way of finding out, and if not, any possibility of
adding that capability? I expect other LAVC managers would greatly appreciate
it!


T.RTitleUserPersonal
Name
DateLines
269.1VWSENG::KLEINSORGEToys 'R' UsWed Feb 22 1989 10:235
    
    Adding that feature sounds like a real security hole to me the way
    the pause feature is implemented!
    

269.2QUARK::LIONELAd AstraWed Feb 22 1989 10:317
I've wished for this feature too.  What I'd like is a resource name that, if
set, specifies a temporary process name for the session manager while the
workstation is paused.  I have people frantically trying to PHONE me at
night, thinking I'm working, because they see the sessions logged in.

				Steve

269.3is this a good thing anyway?HIBOB::VANLAANENJohn VanLaanen CXO1-1/P26, dtn 522-2310Wed Feb 22 1989 15:558
re .1	I agree, depending on just a process name isn't security at all,
	but its better than nothing. Having something that was secure
	would be infinitely preferrable.

	A more general question: Is pausing a session overnight ( especially
	by a priv'd user ) a significant securoty risk? Should we 'encourage'
	our users not to do this?

269.4ATSE::DAVIDSONWed Feb 22 1989 17:4412
    re .3
    
    	I'd say if you have lost physical security of your hardware you
    	might as well give up.  Having a long enough password should keep
    	someone from just walking up and using your system but if they know
    	how to press the halt button you have lost the world anyway if it
    	is a standalone machine.  If it's in a LAVC then you should not
    	allow conv_boot and that will make the system useless if someone
    	just halts it.
    
    Sean

269.5VWSENG::KLEINSORGEToys 'R' UsThu Feb 23 1989 10:437
    
    I repeat, adding this is a gaping and huge security hole.  And if
    you can't figure out *why* then I'll wait for the feature and break
    into *your* account.
    
    

269.6PSW::WINALSKIPaul S. WinalskiThu Feb 23 1989 17:1410
A program that can talk to the server can tell if the session is paused by
locating the session manager's pause window and seeing if it is mapped and
visible.  This is how my modified fish and kaleidoscope programs implement the
-p (draw into the session manager's pause window) and -h (hibernate when the
session is paused) options.

I fail to see how this constitutes a security hole of any sort.

--PSW

269.7Cost Center manager's problem not the system manager'sTOHOKU::TAYLORMon Feb 27 1989 12:0815
    re: .0 no way for the system manager to tell if it is paused or
           not ( i.e. security paranoia ).

    I can only assume that you have either chained your system manager
    to a desk or that you physically secured the workstations from
    access. 

    Leaving terminals, and now workstations, active is a people
    problem best solved by having someone walk around and see who is
    leaving their terminals active and then taking the appropriate
    "educational" actions. 

    mike

269.8Can PAUSE be disabled?TFH::MCGUIRESoftware DrivenMon Feb 27 1989 16:2813
    On a different but related topic:
    
    	Is there any way to DISABLE the pause session feature for all
        users?
    
    	( Our problem is we have several users who 'reserve' common-use
          work-stations by logging in and entering 'pause' mode while
          at lunch, meetings, etc. )
    
    -Gerry
    
                     

269.9KONING::KONINGNI1D @FN42eqMon Feb 27 1989 17:076
The Reboot button would take appropriate care of such people.  (Or you might
try typing random passwords a lot of times and letting breakin evasion
disable their account...)

	paul

269.10Try *PauseButton.sensitive: FalseMCNALY::MILLERBush For President...Kate Bush!Mon Feb 27 1989 17:1711
or something like it...I haven't tried it but I used to have the following to 
disable VUE (*before*VUE got so good ;) because I kept accidentally bringing
up VUE when I really wanted another DECterm:

*VueButton.sensitive:   False

(in decw$xdefaults.dat)
Regards,

             == ken miller ==