Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #81375 > unrolled thread
| Started by | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| First post | 2026-01-20 21:00 +0000 |
| Last post | 2026-01-21 09:12 +0100 |
| Articles | 20 on this page of 106 — 19 participants |
Back to article view | Back to comp.os.linux.misc
“What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 21:00 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” John Ames <commodorejohn@gmail.com> - 2026-01-20 13:15 -0800
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 08:21 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Jason H <jason_hindle@yahoo.com> - 2026-01-21 21:24 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” John Ames <commodorejohn@gmail.com> - 2026-01-21 13:52 -0800
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-20 21:43 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 23:28 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 03:44 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” c186282 <c186282@nnada.net> - 2026-01-20 23:07 -0500
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:15 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:14 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 08:22 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:53 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-21 22:18 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” c186282 <c186282@nnada.net> - 2026-01-20 19:47 -0500
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” vallor <vallor@vallor.earth> - 2026-01-21 01:40 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” c186282 <c186282@nnada.net> - 2026-01-20 20:59 -0500
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” vallor <vallor@vallor.earth> - 2026-01-21 08:50 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:19 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 07:35 -0500
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-21 12:43 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:50 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 19:12 -0500
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-22 00:20 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 10:12 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-22 20:40 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Ralf Fassel <ralfixx@gmx.de> - 2026-01-22 14:45 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Harold Stevens <wookie@aspen.localdomain> - 2026-01-22 09:57 -0600
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 18:51 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-22 20:13 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-22 12:30 -0800
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 05:55 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 14:37 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 22:09 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 23:27 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-20 21:03 -0800
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:19 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:44 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 10:40 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:03 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:29 +0100
Re: “What a Linux root user can do - and 8 w ays you should abso lutely never use it ” vallor <vallor@vallor.earth> - 2026-01-23 14:46 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Richard Kettlewell <invalid@invalid.invalid> - 2026-01-21 08:50 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:19 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-21 18:33 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 14:33 -0500
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-21 21:15 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 18:59 -0500
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-22 05:26 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Pancho <Pancho.Jones@protonmail.com> - 2026-01-21 20:07 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:49 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-21 01:00 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:14 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-21 10:00 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 12:04 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-21 22:32 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:51 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 03:06 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 10:42 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 10:11 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 21:42 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 20:44 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 13:06 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 12:30 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:11 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Andreas Eder <a_eder_muc@web.de> - 2026-01-22 11:24 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 11:52 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 13:08 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Andreas Eder <a_eder_muc@web.de> - 2026-01-22 17:50 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 17:17 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 20:15 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:08 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 22:46 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 11:04 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:32 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 15:00 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 18:16 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” John Ames <commodorejohn@gmail.com> - 2026-01-23 09:32 -0800
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 18:19 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-24 14:22 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-25 09:45 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-25 17:14 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-25 21:52 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-25 15:31 -0800
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-26 12:00 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 21:00 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 22:30 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 22:30 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-24 14:21 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-24 21:05 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-25 15:05 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Stéphane CARPENTIER <sc@fiat-linux.fr> - 2026-01-24 11:31 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-24 14:19 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:30 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:06 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” candycanearter07 <candycanearter07@candycanearter07.nomail.afraid> - 2026-01-23 15:10 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:05 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 22:48 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:32 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 11:40 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 18:17 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 18:20 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 22:36 +0000
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-23 21:44 -0800
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-24 14:23 +0100
Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:12 +0100
Page 3 of 6 — ← Prev page 1 2 [3] 4 5 6 Next page →
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-23 12:29 +0100 |
| Subject | Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” |
| Message-ID | <10kvm2m$3jk82$1@news1.tnib.de> |
| In reply to | #81516 |
Lawrence D´Oliveiro <ldo@nz.invalid> wrote: >On Thu, 22 Jan 2026 10:40:57 +0100, Marc Haber wrote: > >> Lawrence D´Oliveiro <ldo@nz.invalid> wrote: >>> >>> There seems to be this feeling that sudo is overly complicated and >>> prone to its own ongoing security vulnerabilities. >> >> What are the currently ongoing security vulnerabilities in a current >> sudo? I need to know that. > >I did a quick search and found this one ><https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html> >from just a few months ago. Yes, we fixed that two months before that article was published. >The list they linked to shows a couple of other items, one happening >every few years ><https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=sudo&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=20&url=>. Old news. I thought there was a current vulnerabilty that I should have been aware of. >Searching at cve.org shows a new one, from this year ><https://www.cve.org/CVERecord?id=CVE-2026-22536>. I even see a few >mentioning sudo-rs, which is a reimplementation of sudo in Rust. sudo-rs is a totally independent project. I don't know zilch about that one other than Ubuntu has decided to go that way. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | vallor <vallor@vallor.earth> |
|---|---|
| Date | 2026-01-23 14:46 +0000 |
| Subject | Re: “What a Linux root user can do - and 8 w ays you should abso lutely never use it ” |
| Message-ID | <10l01k6$3uuiq$1@dont-email.me> |
| In reply to | #81470 |
At Thu, 22 Jan 2026 10:40:57 +0100, Marc Haber <mh+usenetspam1118@zugschl.us> wrote: > Lawrence D´Oliveiro <ldo@nz.invalid> wrote: > >On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote: > >> ... and thus the better control possibilities that sudo offers are > >> moot. > > > >There seems to be this feeling that sudo is overly complicated and > > That surely is not a very wrong stance. sudo is quite complicated, and > I would probably have stopped using it (chaning to either runas from > the BSD universe or run0 from systemd) if I weren't maintaining the > Debian packages. > > Configuring sudo to require the targetpw doesn't help with that AT > ALL, it just makes things worse. I agree in the case of multiple users that have to sudo to root...but I was referring to my machine at home, with only me as a possible superuser. If I boot to a recovery console, it needs my root password anyway, so having that separate would almost seem to make sense. ;) > > >prone to its own ongoing security vulnerabilities. > > What are the currently ongoing security vulnerabilities in a current > sudo? I need to know that. > > Greetings > Marc -- -v System76 Thelio Mega v1.1 x86_64 Mem: 258G OS: Linux 6.18.5 D: Mint 22.3 DE: Xfce 4.18 (X11) NVIDIA GeForce RTX 3090Ti (24G) (580.105.08) "How come the AT&T logo looks like the Death Star?"
[toc] | [prev] | [next] | [standalone]
| From | Richard Kettlewell <invalid@invalid.invalid> |
|---|---|
| Date | 2026-01-21 08:50 +0000 |
| Message-ID | <wwvldhr8i3y.fsf@LkoBDZeT.terraraq.uk> |
| In reply to | #81392 |
c186282 <c186282@nnada.net> writes: > On 1/20/26 16:43, rbowman wrote: >> Lawrence D’Oliveiro wrote: >>> Yeah, but sudo *is* for running things as root! You think running them >>> via sudo is any better than however else you were thinking of doing >>> those things as root? >> >> Sudo limits the damage. Become root with 'sudo su -' and you'd >> better not have lapses of attention. I think it was OpenSUSE where if >> you were root the wallpaper turned bright red with round, black bombs >> with smoking fuses. > > 'sudo', as often implemented, is NOT safe. PI-os > doesn't even ask for yer user PW. > > You CAN tweak sudoers ... tighten things up a bit, > but that's more work and, if like me, you never > use 'visudo', just 'nano', you'd better get the > syntax right. > > The alt is to have NO 'sudo'. If you are concerned > about security then this may be the best and easiest > path. Open a terminal, 'su', then you need the ROOT > password. In security terms, all these options (su, sudo with password, sudo without password) are largely the same. An attacker who compromises your non-root account can capture any password you enter via it. The password requirement is more like a speedbump than a barrier. -- https://www.greenend.org.uk/rjk/
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-21 11:19 +0100 |
| Message-ID | <10kq97r$31q79$1@news1.tnib.de> |
| In reply to | #81392 |
c186282 <c186282@nnada.net> wrote: > 'sudo', as often implemented, is NOT safe. It has other unsafeties than "su" > PI-os > doesn't even ask for yer user PW. > > You CAN tweak sudoers ... tighten things up a bit, > but that's more work and, if like me, you never > use 'visudo', just 'nano', you'd better get the > syntax right. I find Debian's default sudoers¹ pretty sane. Changing configuration as clear as sudoers rarely counts as "tweaking". > The alt is to have NO 'sudo'. If you are concerned > about security then this may be the best and easiest > path. Open a terminal, 'su', then you need the ROOT > password. The ONE root password that you need to share at least with the team if not with the whole company. And then change it everytime someone leaves, which will inevitably lead to people writing down the sudo password of the day. I'd rather have a policy of "root login via ssh forbidden, noone knows the full root password², sysadmin people encouraged to have strong user passwords, logging in via ssh key only". That way, you have two factors (ssh key plus its passphrase to log in) for regular user privileges, one additional factor (the user-specific password that canoot be used to log in) to be root, with the possibility of locking individual persons out without crippling the whole team. The authorized keys, user passwords and the actual group membership needed to sudo is regulaly brought in via a directory service and sssd. The "real" root password stays for emergency access. Of course you need to trust all people having root privileges to not leave a backdoor, but there's not silver bullet for _THAT_. This is the setup used in the vast majority of Linux-using environments I have ever worked with, even and especially the big ones with their number of installations in the five-digit range. In a modern environment with a strictly controlled production and automatic configuration management, one could strive for a login-free production, doing everything through configuration management, flagging any production machine that somebody had logged into for reinstallation. The most professional organisation I have ever experienced does this for development and staging. They don't have user accounts in production, just an "admin" account that allows ssh certificates from their ssh CA to log in. If you need to log in to production, you go to a web frontend and get a ssh certificate issued that is valid for three hours for THIS machine. A ticket is automatically opened and you need to explain WHY you had to log in and what you did. The machine in question will be reinstalled throug the following night. I am really impressed by that setup. Greetings Marc ¹ disclaimer: I am the person who has the last word about what goes in there or not. ² a good method would be to divide the root password into shards, using the excellent ssss tool, requiring for example three out of five shardholders to agree that the root password is needed. -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | rbowman <bowman@montana.com> |
|---|---|
| Date | 2026-01-21 18:33 +0000 |
| Message-ID | <mtckf4F2g9qU1@mid.individual.net> |
| In reply to | #81420 |
On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote: > The ONE root password that you need to share at least with the team if > not with the whole company. And then change it everytime someone leaves, > which will inevitably lead to people writing down the sudo password of > the day. At one time all the AIX and Linux boxes in the shop had the same root password -- wolf359. It was a simpler time.
[toc] | [prev] | [next] | [standalone]
| From | Chris Ahlstrom <OFeem1987@teleworm.us> |
|---|---|
| Date | 2026-01-21 14:33 -0500 |
| Message-ID | <10kr9mh$2c7ub$3@dont-email.me> |
| In reply to | #81434 |
rbowman wrote this post by blinking in Morse code:
> On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote:
>
>> The ONE root password that you need to share at least with the team if
>> not with the whole company. And then change it everytime someone leaves,
>> which will inevitably lead to people writing down the sudo password of
>> the day.
>
> At one time all the AIX and Linux boxes in the shop had the same root
> password -- wolf359. It was a simpler time.
All my computers have the password "BR-549" :-)
Oddly there's a band called the same:
<https://www.youtube.com/watch?v=nKJeB03TrJg>
BR5-49 - Even If It's Wrong (Official Video)
Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D
--
The law will never make men free; it is men who have got to make the law free.
-- Henry David Thoreau
[toc] | [prev] | [next] | [standalone]
| From | Charlie Gibbs <cgibbs@kltpzyxm.invalid> |
|---|---|
| Date | 2026-01-21 21:15 +0000 |
| Message-ID | <FlbcR.268063$UIC2.249964@fx11.iad> |
| In reply to | #81435 |
On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote: > All my computers have the password "BR-549" :-) > > Oddly there's a band called the same: > > <https://www.youtube.com/watch?v=nKJeB03TrJg> > > BR5-49 - Even If It's Wrong (Official Video) > > Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D Even more oddly, the band took it from a skit on the TV show "Hee Haw", where Junior Samples would play a used car salesman who invited people to telephone him at BR-549. https://en.wikipedia.org/wiki/Junior_Samples#BR-549 -- /~\ Charlie Gibbs | Growth for the sake of \ / <cgibbs@kltpzyxm.invalid> | growth is the ideology X I'm really at ac.dekanfrus | of the cancer cell. / \ if you read it the right way. | -- Edward Abbey
[toc] | [prev] | [next] | [standalone]
| From | Chris Ahlstrom <OFeem1987@teleworm.us> |
|---|---|
| Date | 2026-01-21 18:59 -0500 |
| Message-ID | <10krp9u$2htvf$3@dont-email.me> |
| In reply to | #81440 |
Charlie Gibbs wrote this post by blinking in Morse code:
> On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote:
>
>> All my computers have the password "BR-549" :-)
>>
>> Oddly there's a band called the same:
>>
>> <https://www.youtube.com/watch?v=nKJeB03TrJg>
>>
>> BR5-49 - Even If It's Wrong (Official Video)
>>
>> Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D
>
> Even more oddly, the band took it from a skit on the TV show
> "Hee Haw", where Junior Samples would play a used car salesman
> who invited people to telephone him at BR-549.
Yes, that was the second YouTube link above.
> https://en.wikipedia.org/wiki/Junior_Samples#BR-549
When I was a grad student at Vandy, when we had some visiting
big-wig professors, I was tasked with driving them to/from their
hotel in a van.
At the hotel, I saw Archie Campbell and Junior Samples, gave them
a wave and got a desultory wave back.
Watched them a lot in rural Illinois. Corn pone humor.
Staffers of the John F. Kennedy administration famously
referred to Lyndon Johnson as “Uncle Cornpone.”
--
It's better to burn out than it is to rust.
[toc] | [prev] | [next] | [standalone]
| From | Charlie Gibbs <cgibbs@kltpzyxm.invalid> |
|---|---|
| Date | 2026-01-22 05:26 +0000 |
| Message-ID | <PxicR.784$jWN.366@fx21.iad> |
| In reply to | #81456 |
On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote: > Charlie Gibbs wrote this post by blinking in Morse code: > >> On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote: >> >>> All my computers have the password "BR-549" :-) >>> >>> Oddly there's a band called the same: >>> >>> <https://www.youtube.com/watch?v=nKJeB03TrJg> >>> >>> BR5-49 - Even If It's Wrong (Official Video) >>> >>> Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D >> >> Even more oddly, the band took it from a skit on the TV show >> "Hee Haw", where Junior Samples would play a used car salesman >> who invited people to telephone him at BR-549. > > Yes, that was the second YouTube link above. Oops, missed that. As soon as I saw your password I heard Junior Samples' voice saying "BR-fahve-fore-nahn". In some other skits a character would get him to spell "Mississippi" - which came out "M dotted-line crooked-letter crooked-letter dotted-line crooked-letter crooked-letter dotted-line humpback humpback I". (Yes, he said the final "I" normally to get in one last twist. -- /~\ Charlie Gibbs | Growth for the sake of \ / <cgibbs@kltpzyxm.invalid> | growth is the ideology X I'm really at ac.dekanfrus | of the cancer cell. / \ if you read it the right way. | -- Edward Abbey
[toc] | [prev] | [next] | [standalone]
| From | Pancho <Pancho.Jones@protonmail.com> |
|---|---|
| Date | 2026-01-21 20:07 +0000 |
| Message-ID | <10krbll$2dfnf$1@dont-email.me> |
| In reply to | #81434 |
On 1/21/26 18:33, rbowman wrote: > On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote: > >> The ONE root password that you need to share at least with the team if >> not with the whole company. And then change it everytime someone leaves, >> which will inevitably lead to people writing down the sudo password of >> the day. > > At one time all the AIX and Linux boxes in the shop had the same root > password -- wolf359. It was a simpler time. Back in the day... Readable /etc/passwd, including hashed password. Thousands of users with the same hash. Fuckwits...
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-21 23:49 +0000 |
| Message-ID | <10krom4$2hv00$2@dont-email.me> |
| In reply to | #81436 |
On Wed, 21 Jan 2026 20:07:17 +0000, Pancho wrote: > Readable /etc/passwd, including hashed password. It meant that a program didn’t need privilege to verify that the user knew the password for the account they were on. Quite a few programs back in that era got used to being able to obtain the password hash via getpwent(3). I think it was Sun that introduced the (non-world-readable) /etc/shadow file, and everybody else, reluctantly, agreed it was a good idea, even if it broke a few useful programs. That was the time I learned a new phrase: “dictionary attack” ...
[toc] | [prev] | [next] | [standalone]
| From | Charlie Gibbs <cgibbs@kltpzyxm.invalid> |
|---|---|
| Date | 2026-01-21 01:00 +0000 |
| Message-ID | <tyVbR.18984$Al3.12122@fx20.iad> |
| In reply to | #81378 |
On 2026-01-20, rbowman <bowman@montana.com> wrote: > On Tue, 20 Jan 2026 21:00:59 -0000 (UTC), Lawrence D’Oliveiro wrote: > >> Yeah, but sudo *is* for running things as root! You think running them >> via sudo is any better than however else you were thinking of doing >> those things as root? > > Sudo limits the damage. Become root with 'sudo su -' and you'd better not > have lapses of attention. I think it was OpenSUSE where if you were root > the wallpaper turned bright red with round, black bombs with smoking > fuses. I wonder whether Matt Stone and Trey Parker used that system. Maybe it inspired "Spooky Vision", where in the South Park episode "Spooky Fish" a picture of Barbra Streisand's head is shown in each corner of the screen. -- /~\ Charlie Gibbs | Growth for the sake of \ / <cgibbs@kltpzyxm.invalid> | growth is the ideology X I'm really at ac.dekanfrus | of the cancer cell. / \ if you read it the right way. | -- Edward Abbey
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-21 09:14 +0100 |
| Message-ID | <10kq1sl$314kf$1@news1.tnib.de> |
| In reply to | #81378 |
rbowman <bowman@montana.com> wrote: >Become root with 'sudo su -' See my posting from a minute ago and read up about sudo -i. And then don't use it. >I think it was OpenSUSE where if you were root >the wallpaper turned bright red with round, black bombs with smoking >fuses. Don't ever ever start a desktop environment as root. My shell prompt becomes red when I'm root. That happens seldomly enough. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2026-01-21 10:00 +0000 |
| Message-ID | <10kq83d$20kk7$2@dont-email.me> |
| In reply to | #81408 |
On 21/01/2026 08:14, Marc Haber wrote:
> rbowman <bowman@montana.com> wrote:
>> Become root with 'sudo su -'
>
> See my posting from a minute ago and read up about sudo -i. And then
> don't use it.
>
>> I think it was OpenSUSE where if you were root
>> the wallpaper turned bright red with round, black bombs with smoking
>> fuses.
>
> Don't ever ever start a desktop environment as root.
>
I cant imagine why I would ever want to...
> My shell prompt becomes red when I'm root. That happens seldomly
> enough.
>
> Greetings
> Marc
--
“I know that most men, including those at ease with problems of the
greatest complexity, can seldom accept even the simplest and most
obvious truth if it be such as would oblige them to admit the falsity of
conclusions which they have delighted in explaining to colleagues, which
they have proudly taught to others, and which they have woven, thread by
thread, into the fabric of their lives.”
― Leo Tolstoy
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-21 12:04 +0100 |
| Message-ID | <10kqbse$320oc$1@news1.tnib.de> |
| In reply to | #81419 |
The Natural Philosopher <tnp@invalid.invalid> wrote: >On 21/01/2026 08:14, Marc Haber wrote: >> Don't ever ever start a desktop environment as root. >> >I cant imagine why I would ever want to... It's the natural thing to do when you're just migrating over from Windows, have not yet learned all those Linux ropes and want to do administrative stuff. Even a few years ago it was the way to DO administrative stuff with the GUIs before the desktop environments learned how to do proper privilege escalation inside a user session. I think this has only gained some traction recently because of polkit. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-21 22:32 +0100 |
| Message-ID | <99t74mxr57.ln2@Telcontar.valinor> |
| In reply to | #81419 |
On 2026-01-21 11:00, The Natural Philosopher wrote: > On 21/01/2026 08:14, Marc Haber wrote: >> rbowman <bowman@montana.com> wrote: >>> Become root with 'sudo su -' >> >> See my posting from a minute ago and read up about sudo -i. And then >> don't use it. >> >>> I think it was OpenSUSE where if you were root >>> the wallpaper turned bright red with round, black bombs with smoking >>> fuses. >> >> Don't ever ever start a desktop environment as root. >> > I cant imagine why I would ever want to... I can. For instance, when installing the computer and need to do many things as root. Saves time. When repairing the computer, /home is out of commission, and text login does not work, for some reason. You need to use GUI tools as root, /home is out of commission. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-21 23:51 +0000 |
| Message-ID | <10kropj$2hv00$4@dont-email.me> |
| In reply to | #81444 |
On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote: > When repairing the computer, /home is out of commission, and text > login does not work, for some reason. If text logins don’t work, how would you expect GUI logins to work?
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-22 03:06 +0100 |
| Message-ID | <b9d84mxcfh.ln2@Telcontar.valinor> |
| In reply to | #81455 |
On 2026-01-22 00:51, Lawrence D’Oliveiro wrote: > On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote: > >> When repairing the computer, /home is out of commission, and text >> login does not work, for some reason. > > If text logins don’t work, how would you expect GUI logins to work? I have seen it happen once. Nobody could login in text mode because one of the tools doing it was broken in an update, while the graphical login used different tools. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-22 10:42 +0100 |
| Message-ID | <10ksrdb$3a0pk$1@news1.tnib.de> |
| In reply to | #81462 |
"Carlos E.R." <robin_listas@es.invalid> wrote: >On 2026-01-22 00:51, Lawrence D’Oliveiro wrote: >> On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote: >> >>> When repairing the computer, /home is out of commission, and text >>> login does not work, for some reason. >> >> If text logins don’t work, how would you expect GUI logins to work? > >I have seen it happen once. > >Nobody could login in text mode because one of the tools doing it was >broken in an update, while the graphical login used different tools. I find it interesting which exotic use cases people cough up to justify their own every-day insecure usage. -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2026-01-22 10:11 +0000 |
| Message-ID | <10kst5b$2t8jm$4@dont-email.me> |
| In reply to | #81471 |
On 22/01/2026 09:42, Marc Haber wrote: > "Carlos E.R." <robin_listas@es.invalid> wrote: >> On 2026-01-22 00:51, Lawrence D’Oliveiro wrote: >>> On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote: >>> >>>> When repairing the computer, /home is out of commission, and text >>>> login does not work, for some reason. >>> >>> If text logins don’t work, how would you expect GUI logins to work? >> >> I have seen it happen once. >> >> Nobody could login in text mode because one of the tools doing it was >> broken in an update, while the graphical login used different tools. > > I find it interesting which exotic use cases people cough up to > justify their own every-day insecure usage. > Being root is not ordinary everyday usage. It is for emergencies and dramatic reconfigurations. I guess by your standards having a full backup isn't justified either.. -- Climate Change: Socialism wearing a lab coat.
[toc] | [prev] | [next] | [standalone]
Page 3 of 6 — ← Prev page 1 2 [3] 4 5 6 Next page →
Back to top | Article view | comp.os.linux.misc
csiph-web