GNOME Bugzilla – Bug 578385
Default PolicyKit configuration is way too permissive
Last modified: 2010-01-14 01:20:51 UTC
The default PolicyKit settings for the clock applet mechanism allow anyone to change the system clock, without authenticating as root. This has serious security implications, it allows for example to tamper with timestamps in log files by changing the system time.
Created attachment 132340 [details] [review] Suggested changes in the default policy
Hi, I think changing to auth_admin* makes sense, though exactly which could be debated. Thanks, James
Fixed, except for the timezone: it cannot harm the computer in any serious way, afaik.
*** Bug 590630 has been marked as a duplicate of this bug. ***