retsaw said:
All in all this isn't nearly as secure as it should be, even though I don't think it is anything to panic about.
Although I completely agree with all the principles stated in the previous post (I have them in place in my One), I have to say that some of them are of little relevance for a system like this.
Safety is already fully compromised in a system like this (or any other laptop), because the first rule for a safe system is to deny direct physical access to the system for any unauthorized personnel. But this rule, if applied would probably render a laptop useless...
Apple Mac OS X systems with factory configuration (desktop or laptop) are quite easy to crack if you can have access to the keyboard. You just need to restart the computer and press a combination of keys at the startup for system maintenance mode, them remount the file system read/write, and then change the root password with passwd (you can do this in much less than 5 minutes; the limiting steep is the boot speed). You can even store the original password file so that you can cover your track before leaving the system.
Any other mainstream system without a BIOS password and/or encrypted file system is also quite easy to crack, if you have physical access to it (at most, you need a live cd or equivalent).
If you have a BIOS password, but someone can easily open your computer case , it is usually also easy to remove the BIOS password. However, this will take more time (about 15 minutes for a well trained person; maybe less...) in the case of the AAO, and you get the automatic bonus of intrusion detection since you would notice the missing/changed password.
The only effective protection in the long run would be to have an encrypted file system (although this is not also bullet proof, and does have its own draw backs)...
In any case, you also have to be careful with your backup copies (it is a big security hole to grant access to these)...
I believe that many of the AAO owners will have a single account there and will not share the netbook. In this case, it is also not that relevant to have shadow passwords. You can always lock the screen if you are leaving the netbook unattended.