Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #178505
| From | Joe <joe@jretrading.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: [SOLVED] Re: Security hole in LXDE? |
| Date | 2017-03-06 21:00 +0100 |
| Message-ID | <ti6Xv-4vE-9@gated-at.bofh.it> (permalink) |
| References | (3 earlier) <ti4Cm-2Wx-17@gated-at.bofh.it> <ti5I6-3Hy-19@gated-at.bofh.it> <ti5RM-3Nc-33@gated-at.bofh.it> <ti61s-3R8-9@gated-at.bofh.it> <ti6E9-4o1-5@gated-at.bofh.it> |
| Organization | JRE Trading Ltd |
On Mon, 6 Mar 2017 19:36:40 +0000 Brian <ad44@cityscape.co.uk> wrote: > On Mon 06 Mar 2017 at 18:59:18 +0000, Joe wrote: > > > On Mon, 6 Mar 2017 13:40:45 -0500 > > Greg Wooledge <wooledg@eeg.ccf.org> wrote: > > > > > On Mon, Mar 06, 2017 at 06:31:46PM +0000, Joe wrote: > > > > Debian appears to use the group 'sudo' as an administrative > > > > group, where some other distributions use 'wheel'. > > > > > > > > I would not have thought that users would be added to it by > > > > default, there are no members on my sid/xfce4 workstation. > > > > Indeed, up to Jessie, sudo was not installed at all by default, > > > > and may still not be. > > > > > > If you use the regular Debian installer, the user account that you > > > create during installation gets added to a lot of these special > > > groups (sudo, cdrom, floppy, audio, video, ...?). Users that you > > > create post-installtion using adduser or useradd do not. > > > > > > > New behaviour, then, my current sid was installed as wheezy, I added > > sudo manually early on, but as it was not installed by default, it > > would not have added the installing user to a sudo group. I'm > > certainly not a member of that group, and have no wish to be. > > The "first user" is not in the sudo group. The place to check this > is the templates file in the user-setup-udeb package. > > > Possibly I'm missing something, but doesn't this repeat the Windows > > mistake of automatically giving the user admin privileges? Isn't > > that the main reason for the existence of so many Windows viruses? > > Look at it this way. The "first user" wishes to set up a printer. Is > it better for the user to be granted very limited privileges by being > in the lpadmin group or to become root to carry out the task? > Who said anything about lpadmin? The question is about the wisdom of automatically including someone in the sudo group, which in a default Debian sudoers file, gives full root privileges to everything, using the user's password. We have someone saying this happens, someone else saying it doesn't, I don't know as I haven't done a recent installation, and the thread was started by someone who says it did happen to him. -- Joe
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 10:30 +0100
Re: Security hole in LXDE? Jonathan Dowland <jmtd@debian.org> - 2017-02-27 11:00 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:20 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 16:40 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 11:50 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 12:40 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 13:20 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 14:20 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 14:40 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:20 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-03-02 15:10 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:40 +0100
[SOLVED] Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-06 18:30 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 19:40 +0100
Re: [SOLVED] Re: Security hole in LXDE? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-03-06 19:50 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 20:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 20:40 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 21:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? Curt <curty@free.fr> - 2017-03-06 21:50 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 22:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 22:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-07 13:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-06 20:50 +0100
Re: Security hole in LXDE? Davor Balder <davor@cropakglobal.com> - 2017-02-27 11:10 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:30 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 12:20 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-27 23:00 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-28 11:10 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-28 13:40 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
Re: Security hole in LXDE? Lisi Reisz <lisi.reisz@gmail.com> - 2017-03-01 01:00 +0100
Re: Security hole in LXDE? cbannister@slingshot.co.nz - 2017-03-25 07:20 +0100
Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:10 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 12:30 +0100
Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:50 +0100
Re: Security hole in LXDE? Pontus Goffe <goffe.pontus@gmail.com> - 2017-02-27 15:50 +0100
csiph-web