Re: What's so secure about sudo?
אורי <[email protected]> Tue, 18 Jun 2019 16:23:25 +0300
| Newsgroups | gmane.linux.region.israel |
|---|---|
| Message-ID | <CABD5YeHnAqPbO4_F4TeACEBcDxztdwB17_zP0zq60YvgqzzBaw@mail.gmail.com> |
--===============1145381060746247696== Content-Type: multipart/alternative; boundary="0000000000003686ea058b990b7c" --0000000000003686ea058b990b7c Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I'm not an expert, but I found out that if I login as a regular user, I use sedo only when necessary. But when I login as root (which I do) I am root all the time. This may cause problems if by mistake I enter a command which might cause a big damage as root, but not a big damage as a regular user. Such as, for example, rm -f. So the security issue is also for me entering as a legitimate user and accidentally writing a wrong command. Which will probably not happen with sedo. Especially when sedos require for me to enter my password. Anyway, some servers I manage I am able to login as root and some not, as root login there is disabled. I'm not an expert is security but I think usually my servers are not cracked/hacked as long as I keep the passwords secure. If I login as root and don't make mistakes such as above, I don't see why logging in as root is less secure than sedo. By the way, sometimes I login as a regular user and then su. I don't remember if this option is enabled in all my servers. =D7=90=D7=95=D7=A8=D7=99 [email protected] On Tue, Jun 18, 2019 at 9:24 AM Shlomo Solomon <[email protected]> wrote: > This has bothered me for years and I decided to "get it off my chest". > > For many years I used su to do administrative tasks, but "everyone" > uses sudo and the claim is that it's more secure than actually logging > in as root. > > In principal, of course, root login is not a good thing, but let's > remember something I've never seen discussed. I would assume that on > most systems the root password is MUCH more secure than that of a > regular user. Now if I give user david sudo privileges, anyone who > cracks david's (weak) password now has access to root privileges. > > And before anyone says that this is only a one-time authorization, what > if the guy who cracked david's password now does: > sudo passwd root > > So what's so secure about using sudo? > > -- > Shlomo Solomon > http://the-solomons.net > Claws Mail 3.16.0 - Kubuntu 18.04 > > _______________________________________________ > Linux-il mailing list > [email protected] > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > --0000000000003686ea058b990b7c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">I'm not an expert, but I found out that if I login as = a regular user, I use sedo only when necessary. But when I login as root (w= hich I do) I am root all the time. This may cause problems if by mistake I = enter a command which might cause a big damage as root, but not a big damag= e as a regular user. Such as, for example, rm -f. So the security issue is = also for me entering as a legitimate user and accidentally writing a wrong = command. Which will probably not happen with sedo. Especially when sedos re= quire for me to enter my password.<div><br></div><div>Anyway, some servers = I manage I am able to login as root and some not, as root login there is di= sabled. I'm not an expert is security but I think usually my servers ar= e not cracked/hacked as long as I keep the passwords secure. If I login as = root and don't make mistakes such as above, I don't see why logging= in as root is less secure than sedo.</div><div><br></div><div>By the=C2=A0= way, sometimes I login as a regular user and then su. I don't remember = if this option is enabled in all my servers.<br clear=3D"all"><div><div dir= =3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div = dir=3D"ltr"><div><div dir=3D"ltr"><div style=3D"direction:rtl"><div style= =3D"direction:rtl">=D7=90=D7=95=D7=A8=D7=99</div><div style=3D"direction:rt= l"><a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a></= div></div></div></div></div></div></div><br></div></div><br><div class=3D"g= mail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Jun 18, 2019 at 9= :24 AM Shlomo Solomon <<a href=3D"mailto:[email protected]">shlom= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quot= e" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204)= ;padding-left:1ex">This has bothered me for years and I decided to "ge= t it off my chest".<br> <br> For many years I used su to do administrative tasks, but "everyone&quo= t;<br> uses sudo and the claim is that it's more secure than actually logging<= br> in as root. <br> <br> In principal, of course, root login is not a good thing, but let's<br> remember something I've never seen discussed. I would assume that on<br= > most systems the root password is MUCH more secure than that of a<br> regular user. Now if I give user david sudo privileges, anyone who<br> cracks david's (weak) password now has access to root privileges. <br> <br> And before anyone says that this is only a one-time authorization, what<br> if the guy who cracked david's password now does:<br> =C2=A0 =C2=A0 =C2=A0 =C2=A0sudo passwd root<br> <br> So what's so secure about using sudo?=C2=A0 =C2=A0<br> <br> -- <br> Shlomo Solomon<br> <a href=3D"http://the-solomons.net" rel=3D"noreferrer" target=3D"_blank">ht= tp://the-solomons.net</a><br> Claws Mail 3.16.0 - Kubuntu 18.04<br> <br> _______________________________________________<br> Linux-il mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]= i.ac.il</a><br> <a href=3D"http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il" rel=3D"n= oreferrer" target=3D"_blank">http://mailman.cs.huji.ac.il/mailman/listinfo/= linux-il</a><br> </blockquote></div> --0000000000003686ea058b990b7c-- --===============1145381060746247696== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Linux-il mailing list [email protected] http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il --===============1145381060746247696==--