<div dir="ltr"><div class="gmail_default" style="font-family:tahoma,sans-serif">* <a href="https://www.youtube.com/watch?v=o0purspHg-o">https://www.youtube.com/watch?v=o0purspHg-o</a></div><div class="gmail_default" style="font-family:tahoma,sans-serif">* <a href="https://www.bsdcan.org/2014/schedule/attachments/283_2014-04-29%20sudo%20tutorial%20-%20bsdcan%202014.pdf">https://www.bsdcan.org/2014/schedule/attachments/283_2014-04-29%20sudo%20tutorial%20-%20bsdcan%202014.pdf</a></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><span style="font-family:tahoma,sans-serif">--<br>Rabin</span></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, 18 Jun 2019 at 09:25, Shlomo Solomon <<a href="mailto:shlomo.solomon@gmail.com">shlomo.solomon@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">This has bothered me for years and I decided to "get it off my chest".<br>
<br>
For many years I used su to do administrative tasks, but "everyone"<br>
uses sudo and the claim is that it's more secure than actually logging<br>
in as root. <br>
<br>
In principal, of course, root login is not a good thing, but let's<br>
remember something I've never seen discussed. I would assume that on<br>
most systems the root password is MUCH more secure than that of a<br>
regular user. Now if I give user david sudo privileges, anyone who<br>
cracks david's (weak) password now has access to root privileges. <br>
<br>
And before anyone says that this is only a one-time authorization, what<br>
if the guy who cracked david's password now does:<br>
sudo passwd root<br>
<br>
So what's so secure about using sudo? <br>
<br>
-- <br>
Shlomo Solomon<br>
<a href="http://the-solomons.net" rel="noreferrer" target="_blank">http://the-solomons.net</a><br>
Claws Mail 3.16.0 - Kubuntu 18.04<br>
<br>
_______________________________________________<br>
Linux-il mailing list<br>
<a href="mailto:Linux-il@cs.huji.ac.il" target="_blank">Linux-il@cs.huji.ac.il</a><br>
<a href="http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il" rel="noreferrer" target="_blank">http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il</a><br>
</blockquote></div>