I realized a while ago that--at least in my RH6.1/LILO setup,
which I think is fairly standard--someone with physical access
to the machine can take it over without knowing any passwords
at all. Just type "linux 1" at the LILO prompt, and bingo,
you're root and can change the root password without knowing
the old one.
Now, I'm not entirely sure I *want* to change this; it could
come in handy if I ever change the root password and then
promptly forget it, which isn't impossible. But do other
people have it set up so you can't do this? What do you do?
I know of course that if someone has physical access to your
machine he can get your data *eventually* if it's not encrypted,
but I wouldn't think it's supposed to be this easy.