PDA

View Full Version : No access control?



utopiadaniele
January 3rd, 2013, 07:23 AM
Hello everybody,
I am using ubuntu 12.04.1 LTS at home and I am the only user and admin of this machine.
I was very surprised to discover that my 17-y.o. daughter, without using any pwd, logged into the system.

It was enough, while in locked screen mode, to click on "switch user", then to click on "log in" without entering any pwd, and the profile is open to anybody.

Any idea how to fix this?

Thanks a lot, Daniele (from Italy)

Hungry Man
January 3rd, 2013, 07:48 AM
I assume you mean she logged into the guest account?

utopiadaniele
January 3rd, 2013, 07:50 AM
Of course not: to my account! not to the guest one...

Hungry Man
January 3rd, 2013, 07:57 AM
How odd. Can you recreate that? You can just open the system and log in?

akshay.bhardwaj
January 3rd, 2013, 08:05 AM
I guess you have enabled automatic login in User Accounts. Try to get to System Settings>User Accounts and see that automatic login is enabled or not.

utopiadaniele
January 3rd, 2013, 05:18 PM
You were right, automatic login was in fact on.
BUT, even switching it to OFF....... I can log in anyway!!!

I will explain it as I do it (and in fact recreate it!).

Lock screen.

If I try to log in with no pwd --> no way, still locked.

But if I "switch user", and then "log in" (without entering any pwd!!) --> I log in!!!!

weird behaviour...

utopiadaniele
January 3rd, 2013, 05:21 PM
Let me also add that there is no "guest" account: just mine (administrator profile).

Thanks, Daniele

Ms. Daisy
January 3rd, 2013, 06:19 PM
Let me also add that there is no "guest" account: just mine (administrator profile).

Thanks, Daniele

Ubuntu comes with a guest account by default. Unless you specifically removed it,when you change user accounts you are changing to the guest account.

utopiadaniele
January 3rd, 2013, 06:47 PM
Great, that is new to me, thanks.

I will try to insert a (new) guest account and then verify if I can switch my profile back to admin with pwd.
If so, that will be ok for my profile access, but still my machine can be used by my 17 yo daughter... :-) how to lock it and that's it?

utopiadaniele
January 3rd, 2013, 07:05 PM
Did so.
News.

I tried to set the "guest account" with a pwd, that was actually considered by the system too weak and would not accept it.
Then I tried with a stronger pwd, and in fact guest account worked fine: it would not log in without its pwd.

So I thought that maybe the system was considering my admin pwd too weak, and I tried to change it.
First, I set the admin access as "no pwd" at all. It actually worked, it would access after locking the screen without even prompting for a pwd.
But when I secondly tried to change it to a stronger one, it is now asking for an "actual pwd" that is not recognised anymore (nor blank nor the previous one). So I am stuck again.

I am coming to the conclusion that my pwd was (considered) too weak, and therefore it was maybe not recognized as a pwd by the system, whoch would log in without it.

I am trying now to switch down and restart, and hope that it accepts the old one, or the blank pwd.

In any case, it looks like a small bug.

Thanks, Daniele

utopiadaniele
January 3rd, 2013, 07:16 PM
:popcorn: I was wrong, and I found it's no bug. Just I needed to check "Users and Groups" and not "User accounts". Under the "password" section one may choose whether to ask for a pwd at login or not.

TOO EASY!!!!

Of course now it works properly.
I have removed the "guest" account and the admin is correctly logging in ONLY AFTER its proper password is inserted.

cariboo
January 3rd, 2013, 07:18 PM
You can disable the guest account in lightdm using the following command:


sudo /usr/lib/lightdm/lightdm-set-defaults --allow-guest false

or you can disable by editing /etc/light/lightdm.conf. Open lightdm with a text editor:


sudo gedit /etc/lightdm/lightdm.conf

then setting:


allow-guest=false

in the [SeatDefaults] section.

For more info on setting up lightdm, have a look at:

https://wiki.ubuntu.com/LightDM

utopiadaniele
January 4th, 2013, 08:18 AM
Thanks a lot, I am reading through the LightDM pages and it's indeed interesting.

Thanks, Daniele