[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: New Debian user



Roberto C. Sanchez wrote:
> On Tue, Dec 19, 2006 at 05:00:14PM -0600, Kent West wrote:
>   
>> For myself, I just duplicate the existing root line in /etc/sudoers and 
>> then change one of the roots to my user. Granted, this isn't 
>> particularly secure, but it's easy and adds a significant level of 
>> security to doing things as root.
>>     
> Many people seem to mistake sudo for some sort of security panacea.

I reckon I shouldn't have used the word "security" (although my response
here does not in any way reduce the value of your very good post).

What I really meant is that using sudo adds logging (although as you
pointed out, that can be circumvented), and that I'm less likely to do
something stupid running sudo than running as root.

But the basic gist of your post stands: sudo is not a panacea for security.

-- 
Kent West
Westing Peacefully <http://kentwest.blogspot.com>



Reply to: