Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #81375 > unrolled thread

“What a Linux root user can do - and 8 ways you should absolutely never use it”

Started byLawrence D’Oliveiro <ldo@nz.invalid>
First post2026-01-20 21:00 +0000
Last post2026-01-21 09:12 +0100
Articles 20 on this page of 106 — 19 participants

Back to article view | Back to comp.os.linux.misc


Contents

  “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 21:00 +0000
    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” John Ames <commodorejohn@gmail.com> - 2026-01-20 13:15 -0800
      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 08:21 +0000
      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Jason H <jason_hindle@yahoo.com> - 2026-01-21 21:24 +0000
        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” John Ames <commodorejohn@gmail.com> - 2026-01-21 13:52 -0800
    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-20 21:43 +0000
      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 23:28 +0100
        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 03:44 +0000
          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” c186282 <c186282@nnada.net> - 2026-01-20 23:07 -0500
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:15 +0100
          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:14 +0100
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 08:22 +0000
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:53 +0100
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-21 22:18 +0100
      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” c186282 <c186282@nnada.net> - 2026-01-20 19:47 -0500
        Re: “What a Linux root user can do - and 8 ways   you should absolutely never use it” vallor <vallor@vallor.earth> - 2026-01-21 01:40 +0000
          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” c186282 <c186282@nnada.net> - 2026-01-20 20:59 -0500
            Re: “What a Linux root user can do - and 8 ways   you should absolutely never use it” vallor <vallor@vallor.earth> - 2026-01-21 08:50 +0000
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:19 +0100
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 07:35 -0500
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-21 12:43 +0000
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:50 +0000
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 19:12 -0500
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-22 00:20 +0000
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 10:12 +0000
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-22 20:40 +0000
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Ralf Fassel <ralfixx@gmx.de> - 2026-01-22 14:45 +0100
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Harold Stevens <wookie@aspen.localdomain> - 2026-01-22 09:57 -0600
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 18:51 +0100
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-22 20:13 +0000
                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-22 12:30 -0800
                        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 05:55 +0000
                          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 14:37 +0100
                            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 22:09 +0000
                              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 23:27 +0100
          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-20 21:03 -0800
          Re: “What a Linux root user can do - and 8 ways   you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:19 +0100
            Re: “What a Linux root user can do - and 8 ways   you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:44 +0000
              Re: “What a Linux root user can do - and 8 ways   you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 10:40 +0100
                Re: “What a Linux root user can do - and 8 ways   you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:03 +0000
                  Re: “What a Linux root user can do - and 8 ways   you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:29 +0100
                Re: “What a Linux root   user can do - and 8 w  ays   you should abso  lutely never use it  ” vallor <vallor@vallor.earth> - 2026-01-23 14:46 +0000
        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Richard Kettlewell <invalid@invalid.invalid> - 2026-01-21 08:50 +0000
        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 11:19 +0100
          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-21 18:33 +0000
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 14:33 -0500
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-21 21:15 +0000
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Chris Ahlstrom <OFeem1987@teleworm.us> - 2026-01-21 18:59 -0500
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-22 05:26 +0000
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Pancho <Pancho.Jones@protonmail.com> - 2026-01-21 20:07 +0000
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:49 +0000
      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-21 01:00 +0000
      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:14 +0100
        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-21 10:00 +0000
          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 12:04 +0100
          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-21 22:32 +0100
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-21 23:51 +0000
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 03:06 +0100
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 10:42 +0100
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 10:11 +0000
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-22 21:42 +0100
                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 20:44 +0000
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 13:06 +0100
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 12:30 +0000
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:11 +0000
            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Andreas Eder <a_eder_muc@web.de> - 2026-01-22 11:24 +0100
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 11:52 +0000
              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 13:08 +0100
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Andreas Eder <a_eder_muc@web.de> - 2026-01-22 17:50 +0100
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-22 17:17 +0000
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 20:15 +0100
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:08 +0000
                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 22:46 +0100
                        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 11:04 +0000
                        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:32 +0100
                          Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 15:00 +0100
                            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 18:16 +0100
                              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” John Ames <commodorejohn@gmail.com> - 2026-01-23 09:32 -0800
                              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 18:19 +0000
                                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-24 14:22 +0100
                                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-25 09:45 +0000
                                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2026-01-25 17:14 +0000
                                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-25 21:52 +0100
                                        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-25 15:31 -0800
                                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-26 12:00 +0000
                            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 21:00 +0000
                              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 22:30 +0100
                            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 22:30 +0000
                              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-24 14:21 +0100
                                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-24 21:05 +0000
                                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-25 15:05 +0100
                            Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Stéphane CARPENTIER <sc@fiat-linux.fr> - 2026-01-24 11:31 +0000
                              Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-24 14:19 +0100
                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:30 +0100
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:06 +0000
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” candycanearter07 <candycanearter07@candycanearter07.nomail.afraid> - 2026-01-23 15:10 +0000
                Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-22 21:05 +0000
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” "Carlos E.R." <robin_listas@es.invalid> - 2026-01-22 22:48 +0100
                  Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 12:32 +0100
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 11:40 +0000
                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-23 18:17 +0100
                        Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” The Natural Philosopher <tnp@invalid.invalid> - 2026-01-23 18:20 +0000
                    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” rbowman <bowman@montana.com> - 2026-01-23 22:36 +0000
                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-23 21:44 -0800
                      Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-24 14:23 +0100
    Re: “What a Linux root user can do - and 8 ways you should absolutely never use it” Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-21 09:12 +0100

Page 3 of 6 — ← Prev page 1 2 [3] 4 5 6  Next page →


#81535 — Re: “What a Linux root user can do - and 8 ways you should absolutely never use it”

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-23 12:29 +0100
SubjectRe: “What a Linux root user can do - and 8 ways you should absolutely never use it”
Message-ID<10kvm2m$3jk82$1@news1.tnib.de>
In reply to#81516
Lawrence D´Oliveiro <ldo@nz.invalid> wrote:
>On Thu, 22 Jan 2026 10:40:57 +0100, Marc Haber wrote:
>
>> Lawrence D´Oliveiro <ldo@nz.invalid> wrote:
>>>
>>> There seems to be this feeling that sudo is overly complicated and
>>> prone to its own ongoing security vulnerabilities.
>>
>> What are the currently ongoing security vulnerabilities in a current
>> sudo? I need to know that.
>
>I did a quick search and found this one
><https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html>
>from just a few months ago.

Yes, we fixed that two months before that article was published.

>The list they linked to shows a couple of other items, one happening
>every few years
><https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=sudo&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=20&url=>.

Old news. I thought there was a current vulnerabilty that I should
have been aware of.

>Searching at cve.org shows a new one, from this year
><https://www.cve.org/CVERecord?id=CVE-2026-22536>. I even see a few
>mentioning sudo-rs, which is a reimplementation of sudo in Rust.

sudo-rs is a totally independent project. I don't know zilch about
that one other than Ubuntu has decided to go that way.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81550 — Re: “What a Linux root user can do - and 8 w ays you should abso lutely never use it ”

Fromvallor <vallor@vallor.earth>
Date2026-01-23 14:46 +0000
SubjectRe: “What a Linux root user can do - and 8 w ays you should abso lutely never use it ”
Message-ID<10l01k6$3uuiq$1@dont-email.me>
In reply to#81470
At Thu, 22 Jan 2026 10:40:57 +0100, Marc Haber <mh+usenetspam1118@zugschl.us> wrote:

> Lawrence D´Oliveiro <ldo@nz.invalid> wrote:
> >On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote:
> >> ... and thus the better control possibilities that sudo offers are
> >> moot.
> >
> >There seems to be this feeling that sudo is overly complicated and
> 
> That surely is not a very wrong stance. sudo is quite complicated, and
> I would probably have stopped using it (chaning to either runas from
> the BSD universe or run0 from systemd) if I weren't maintaining the
> Debian packages.
> 
> Configuring sudo to require the targetpw doesn't help with that AT
> ALL, it just makes things worse.

I agree in the case of multiple users that have to sudo to root...but
I was referring to my machine at home, with only me as a possible
superuser.

If I boot to a recovery console, it needs my root password
anyway, so having that separate would almost seem to make
sense. ;)

> 
> >prone to its own ongoing security vulnerabilities.
> 
> What are the currently ongoing security vulnerabilities in a current
> sudo? I need to know that.
> 
> Greetings
> Marc

-- 
-v System76 Thelio Mega v1.1 x86_64 Mem: 258G
   OS: Linux 6.18.5 D: Mint 22.3 DE: Xfce 4.18 (X11)
   NVIDIA GeForce RTX 3090Ti (24G) (580.105.08)
   "How come the AT&T logo looks like the Death Star?"

[toc] | [prev] | [next] | [standalone]


#81415

FromRichard Kettlewell <invalid@invalid.invalid>
Date2026-01-21 08:50 +0000
Message-ID<wwvldhr8i3y.fsf@LkoBDZeT.terraraq.uk>
In reply to#81392
c186282 <c186282@nnada.net> writes:
> On 1/20/26 16:43, rbowman wrote:
>> Lawrence D’Oliveiro wrote:
>>> Yeah, but sudo *is* for running things as root! You think running them
>>> via sudo is any better than however else you were thinking of doing
>>> those things as root?
>>
>> Sudo limits the damage.  Become root with 'sudo su -' and you'd
>> better not have lapses of attention. I think it was OpenSUSE where if
>> you were root the wallpaper turned bright red with round, black bombs
>> with smoking fuses.
>
>   'sudo', as often implemented, is NOT safe. PI-os
>   doesn't even ask for yer user PW.
>
>   You CAN tweak sudoers ... tighten things up a bit,
>   but that's more work and, if like me, you never
>   use 'visudo', just 'nano', you'd better get the
>   syntax right.
>
>   The alt is to have NO 'sudo'. If you are concerned
>   about security then this may be the best and easiest
>   path. Open a terminal, 'su', then you need the ROOT
>   password.

In security terms, all these options (su, sudo with password, sudo
without password) are largely the same. An attacker who compromises your
non-root account can capture any password you enter via it. The password
requirement is more like a speedbump than a barrier.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#81420

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-21 11:19 +0100
Message-ID<10kq97r$31q79$1@news1.tnib.de>
In reply to#81392
c186282 <c186282@nnada.net> wrote:
>   'sudo', as often implemented, is NOT safe.

It has other unsafeties than "su"

> PI-os
>   doesn't even ask for yer user PW.
>
>   You CAN tweak sudoers ... tighten things up a bit,
>   but that's more work and, if like me, you never
>   use 'visudo', just 'nano', you'd better get the
>   syntax right.

I find Debian's default sudoers¹ pretty sane.

Changing configuration as clear as sudoers rarely counts as
"tweaking".

>   The alt is to have NO 'sudo'. If you are concerned
>   about security then this may be the best and easiest
>   path. Open a terminal, 'su', then you need the ROOT
>   password.

The ONE root password that you need to share at least with the team if
not with the whole company. And then change it everytime someone
leaves, which will inevitably lead to people writing down the sudo
password of the day.

I'd rather have a policy of "root login via ssh forbidden, noone knows
the full root password², sysadmin people encouraged to have strong
user passwords, logging in via ssh key only". That way, you have two
factors (ssh key plus its passphrase to log in) for regular user
privileges, one additional factor (the user-specific password that
canoot be used to log in) to be root, with the possibility of locking
individual persons out without crippling the whole team. The
authorized keys, user passwords and the actual group membership needed
to sudo is regulaly brought in via a directory service and sssd. The
"real" root password stays for emergency access.

Of course you need to trust all people having root privileges to not
leave a backdoor, but there's not silver bullet for _THAT_.

This is the setup used in the vast majority of Linux-using
environments I have ever worked with, even and especially the big ones
with their number of installations in the five-digit range.

In a modern environment with a strictly controlled production and
automatic configuration management, one could strive for a login-free
production, doing everything through configuration management,
flagging any production machine that somebody had logged into for
reinstallation.

The most professional organisation I have ever experienced does this
for development and staging. They don't have user accounts in
production, just an "admin" account that allows ssh certificates from
their ssh CA to log in. If you need to log in to production, you go to
a web frontend and get a ssh certificate issued that is valid for
three hours for THIS machine. A ticket is automatically opened and you
need to explain WHY you had to log in and what you did. The machine in
question will be reinstalled throug the following night.

I am really impressed by that setup.

Greetings
Marc

¹ disclaimer: I am the person who has the last word about what goes in
there or not.
² a good method would be to divide the root password into shards,
using the excellent ssss tool, requiring for example three out of five
shardholders to agree that the root password is needed.
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81434

Fromrbowman <bowman@montana.com>
Date2026-01-21 18:33 +0000
Message-ID<mtckf4F2g9qU1@mid.individual.net>
In reply to#81420
On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote:

> The ONE root password that you need to share at least with the team if
> not with the whole company. And then change it everytime someone leaves,
> which will inevitably lead to people writing down the sudo password of
> the day.

At one time all the AIX and Linux boxes in the shop had the same root 
password -- wolf359.  It was a simpler time.

[toc] | [prev] | [next] | [standalone]


#81435

FromChris Ahlstrom <OFeem1987@teleworm.us>
Date2026-01-21 14:33 -0500
Message-ID<10kr9mh$2c7ub$3@dont-email.me>
In reply to#81434
rbowman wrote this post by blinking in Morse code:

> On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote:
>
>> The ONE root password that you need to share at least with the team if
>> not with the whole company. And then change it everytime someone leaves,
>> which will inevitably lead to people writing down the sudo password of
>> the day.
>
> At one time all the AIX and Linux boxes in the shop had the same root 
> password -- wolf359.  It was a simpler time.

All my computers have the password "BR-549" :-)

Oddly there's a band called the same:

    <https://www.youtube.com/watch?v=nKJeB03TrJg>

    BR5-49 - Even If It's Wrong (Official Video)

Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D

-- 
The law will never make men free; it is men who have got to make the law free.
		-- Henry David Thoreau

[toc] | [prev] | [next] | [standalone]


#81440

FromCharlie Gibbs <cgibbs@kltpzyxm.invalid>
Date2026-01-21 21:15 +0000
Message-ID<FlbcR.268063$UIC2.249964@fx11.iad>
In reply to#81435
On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote:

> All my computers have the password "BR-549" :-)
>
> Oddly there's a band called the same:
>
>     <https://www.youtube.com/watch?v=nKJeB03TrJg>
>
>     BR5-49 - Even If It's Wrong (Official Video)
>
> Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D

Even more oddly, the band took it from a skit on the TV show
"Hee Haw", where Junior Samples would play a used car salesman
who invited people to telephone him at BR-549.

https://en.wikipedia.org/wiki/Junior_Samples#BR-549

-- 
/~\  Charlie Gibbs                  |  Growth for the sake of
\ /  <cgibbs@kltpzyxm.invalid>      |  growth is the ideology
 X   I'm really at ac.dekanfrus     |  of the cancer cell.
/ \  if you read it the right way.  |    -- Edward Abbey

[toc] | [prev] | [next] | [standalone]


#81456

FromChris Ahlstrom <OFeem1987@teleworm.us>
Date2026-01-21 18:59 -0500
Message-ID<10krp9u$2htvf$3@dont-email.me>
In reply to#81440
Charlie Gibbs wrote this post by blinking in Morse code:

> On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote:
>
>> All my computers have the password "BR-549" :-)
>>
>> Oddly there's a band called the same:
>>
>>     <https://www.youtube.com/watch?v=nKJeB03TrJg>
>>
>>     BR5-49 - Even If It's Wrong (Official Video)
>>
>> Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D
>
> Even more oddly, the band took it from a skit on the TV show
> "Hee Haw", where Junior Samples would play a used car salesman
> who invited people to telephone him at BR-549.

Yes, that was the second YouTube link above.

> https://en.wikipedia.org/wiki/Junior_Samples#BR-549

When I was a grad student at Vandy, when we had some visiting
big-wig professors, I was tasked with driving them to/from their
hotel in a van.

At the hotel, I saw Archie Campbell and Junior Samples, gave them
a wave and got a desultory wave back.

Watched them a lot in rural Illinois. Corn pone humor.

    Staffers of the John F. Kennedy administration famously
    referred to Lyndon Johnson as “Uncle Cornpone.”

-- 
It's better to burn out than it is to rust.

[toc] | [prev] | [next] | [standalone]


#81468

FromCharlie Gibbs <cgibbs@kltpzyxm.invalid>
Date2026-01-22 05:26 +0000
Message-ID<PxicR.784$jWN.366@fx21.iad>
In reply to#81456
On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote:

> Charlie Gibbs wrote this post by blinking in Morse code:
>
>> On 2026-01-21, Chris Ahlstrom <OFeem1987@teleworm.us> wrote:
>>
>>> All my computers have the password "BR-549" :-)
>>>
>>> Oddly there's a band called the same:
>>>
>>>     <https://www.youtube.com/watch?v=nKJeB03TrJg>
>>>
>>>     BR5-49 - Even If It's Wrong (Official Video)
>>>
>>> Also: <https://www.youtube.com/watch?v=9xhTomqDTzE> :-D
>>
>> Even more oddly, the band took it from a skit on the TV show
>> "Hee Haw", where Junior Samples would play a used car salesman
>> who invited people to telephone him at BR-549.
>
> Yes, that was the second YouTube link above.

Oops, missed that.

As soon as I saw your password I heard Junior Samples' voice
saying "BR-fahve-fore-nahn".

In some other skits a character would get him to spell
"Mississippi" - which came out "M dotted-line crooked-letter
crooked-letter dotted-line crooked-letter crooked-letter
dotted-line humpback humpback I".  (Yes, he said the final
"I" normally to get in one last twist.

-- 
/~\  Charlie Gibbs                  |  Growth for the sake of
\ /  <cgibbs@kltpzyxm.invalid>      |  growth is the ideology
 X   I'm really at ac.dekanfrus     |  of the cancer cell.
/ \  if you read it the right way.  |    -- Edward Abbey

[toc] | [prev] | [next] | [standalone]


#81436

FromPancho <Pancho.Jones@protonmail.com>
Date2026-01-21 20:07 +0000
Message-ID<10krbll$2dfnf$1@dont-email.me>
In reply to#81434
On 1/21/26 18:33, rbowman wrote:
> On Wed, 21 Jan 2026 11:19:35 +0100, Marc Haber wrote:
> 
>> The ONE root password that you need to share at least with the team if
>> not with the whole company. And then change it everytime someone leaves,
>> which will inevitably lead to people writing down the sudo password of
>> the day.
> 
> At one time all the AIX and Linux boxes in the shop had the same root
> password -- wolf359.  It was a simpler time.

Back in the day...  Readable /etc/passwd, including hashed password. 
Thousands of users with the same hash. Fuckwits...

[toc] | [prev] | [next] | [standalone]


#81453

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-21 23:49 +0000
Message-ID<10krom4$2hv00$2@dont-email.me>
In reply to#81436
On Wed, 21 Jan 2026 20:07:17 +0000, Pancho wrote:

> Readable /etc/passwd, including hashed password.

It meant that a program didn’t need privilege to verify that the user
knew the password for the account they were on. Quite a few programs
back in that era got used to being able to obtain the password hash
via getpwent(3).

I think it was Sun that introduced the (non-world-readable)
/etc/shadow file, and everybody else, reluctantly, agreed it was a
good idea, even if it broke a few useful programs.

That was the time I learned a new phrase: “dictionary attack” ...

[toc] | [prev] | [next] | [standalone]


#81394

FromCharlie Gibbs <cgibbs@kltpzyxm.invalid>
Date2026-01-21 01:00 +0000
Message-ID<tyVbR.18984$Al3.12122@fx20.iad>
In reply to#81378
On 2026-01-20, rbowman <bowman@montana.com> wrote:

> On Tue, 20 Jan 2026 21:00:59 -0000 (UTC), Lawrence D’Oliveiro wrote:
>
>> Yeah, but sudo *is* for running things as root! You think running them
>> via sudo is any better than however else you were thinking of doing
>> those things as root?
>
> Sudo limits the damage.  Become root with 'sudo su -' and you'd better not 
> have lapses of attention. I think it was OpenSUSE where if you were root 
> the wallpaper turned bright red with round, black bombs with smoking 
> fuses.

I wonder whether Matt Stone and Trey Parker used that system.  Maybe it
inspired "Spooky Vision", where in the South Park episode "Spooky Fish"
a picture of Barbra Streisand's head is shown in each corner of the screen.

-- 
/~\  Charlie Gibbs                  |  Growth for the sake of
\ /  <cgibbs@kltpzyxm.invalid>      |  growth is the ideology
 X   I'm really at ac.dekanfrus     |  of the cancer cell.
/ \  if you read it the right way.  |    -- Edward Abbey

[toc] | [prev] | [next] | [standalone]


#81408

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-21 09:14 +0100
Message-ID<10kq1sl$314kf$1@news1.tnib.de>
In reply to#81378
rbowman <bowman@montana.com> wrote:
>Become root with 'sudo su -'

See my posting from a minute ago and read up about sudo -i. And then
don't use it.

>I think it was OpenSUSE where if you were root 
>the wallpaper turned bright red with round, black bombs with smoking 
>fuses.

Don't ever ever start a desktop environment as root.

My shell prompt becomes red when I'm root. That happens seldomly
enough.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81419

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2026-01-21 10:00 +0000
Message-ID<10kq83d$20kk7$2@dont-email.me>
In reply to#81408
On 21/01/2026 08:14, Marc Haber wrote:
> rbowman <bowman@montana.com> wrote:
>> Become root with 'sudo su -'
> 
> See my posting from a minute ago and read up about sudo -i. And then
> don't use it.
> 
>> I think it was OpenSUSE where if you were root
>> the wallpaper turned bright red with round, black bombs with smoking
>> fuses.
> 
> Don't ever ever start a desktop environment as root.
> 
I cant imagine why I would ever want to...

> My shell prompt becomes red when I'm root. That happens seldomly
> enough.
> 
> Greetings
> Marc

-- 
     “I know that most men, including those at ease with problems of the 
greatest complexity, can seldom accept even the simplest and most 
obvious truth if it be such as would oblige them to admit the falsity of 
conclusions which they have delighted in explaining to colleagues, which 
they have proudly taught to others, and which they have woven, thread by 
thread, into the fabric of their lives.”

     ― Leo Tolstoy

[toc] | [prev] | [next] | [standalone]


#81426

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-21 12:04 +0100
Message-ID<10kqbse$320oc$1@news1.tnib.de>
In reply to#81419
The Natural Philosopher <tnp@invalid.invalid> wrote:
>On 21/01/2026 08:14, Marc Haber wrote:
>> Don't ever ever start a desktop environment as root.
>> 
>I cant imagine why I would ever want to...

It's the natural thing to do when you're just migrating over from
Windows, have not yet learned all those Linux ropes and want to do
administrative stuff. Even a few years ago it was the way to DO
administrative stuff with the GUIs before the desktop environments
learned how to do proper privilege escalation inside a user session. I
think this has only gained some traction recently because of polkit.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81444

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-21 22:32 +0100
Message-ID<99t74mxr57.ln2@Telcontar.valinor>
In reply to#81419
On 2026-01-21 11:00, The Natural Philosopher wrote:
> On 21/01/2026 08:14, Marc Haber wrote:
>> rbowman <bowman@montana.com> wrote:
>>> Become root with 'sudo su -'
>>
>> See my posting from a minute ago and read up about sudo -i. And then
>> don't use it.
>>
>>> I think it was OpenSUSE where if you were root
>>> the wallpaper turned bright red with round, black bombs with smoking
>>> fuses.
>>
>> Don't ever ever start a desktop environment as root.
>>
> I cant imagine why I would ever want to...

I can.

For instance, when installing the computer and need to do many things as 
root. Saves time.

When repairing the computer, /home is out of commission, and text login 
does not work, for some reason.

You need to use GUI tools as root, /home is out of commission.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81455

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-21 23:51 +0000
Message-ID<10kropj$2hv00$4@dont-email.me>
In reply to#81444
On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote:

> When repairing the computer, /home is out of commission, and text
> login does not work, for some reason.

If text logins don’t work, how would you expect GUI logins to work?

[toc] | [prev] | [next] | [standalone]


#81462

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-22 03:06 +0100
Message-ID<b9d84mxcfh.ln2@Telcontar.valinor>
In reply to#81455
On 2026-01-22 00:51, Lawrence D’Oliveiro wrote:
> On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote:
> 
>> When repairing the computer, /home is out of commission, and text
>> login does not work, for some reason.
> 
> If text logins don’t work, how would you expect GUI logins to work?

I have seen it happen once.

Nobody could login in text mode because one of the tools doing it was 
broken in an update, while the graphical login used different tools.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81471

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-22 10:42 +0100
Message-ID<10ksrdb$3a0pk$1@news1.tnib.de>
In reply to#81462
"Carlos E.R." <robin_listas@es.invalid> wrote:
>On 2026-01-22 00:51, Lawrence D’Oliveiro wrote:
>> On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote:
>> 
>>> When repairing the computer, /home is out of commission, and text
>>> login does not work, for some reason.
>> 
>> If text logins don’t work, how would you expect GUI logins to work?
>
>I have seen it happen once.
>
>Nobody could login in text mode because one of the tools doing it was 
>broken in an update, while the graphical login used different tools.

I find it interesting which exotic use cases people cough up to
justify their own every-day insecure usage.

-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81478

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2026-01-22 10:11 +0000
Message-ID<10kst5b$2t8jm$4@dont-email.me>
In reply to#81471
On 22/01/2026 09:42, Marc Haber wrote:
> "Carlos E.R." <robin_listas@es.invalid> wrote:
>> On 2026-01-22 00:51, Lawrence D’Oliveiro wrote:
>>> On Wed, 21 Jan 2026 22:32:57 +0100, Carlos E.R. wrote:
>>>
>>>> When repairing the computer, /home is out of commission, and text
>>>> login does not work, for some reason.
>>>
>>> If text logins don’t work, how would you expect GUI logins to work?
>>
>> I have seen it happen once.
>>
>> Nobody could login in text mode because one of the tools doing it was
>> broken in an update, while the graphical login used different tools.
> 
> I find it interesting which exotic use cases people cough up to
> justify their own every-day insecure usage.
> 
Being root is not ordinary everyday usage.

It is for emergencies and dramatic reconfigurations.
I guess by your standards having a full backup isn't justified either..

-- 
Climate Change: Socialism wearing a lab coat.

[toc] | [prev] | [next] | [standalone]


Page 3 of 6 — ← Prev page 1 2 [3] 4 5 6  Next page →

Back to top | Article view | comp.os.linux.misc


csiph-web