Re: What's so secure about sudo?

אורי <[email protected]> Tue, 18 Jun 2019 16:23:25 +0300
Newsgroups gmane.linux.region.israel
Message-ID <CABD5YeHnAqPbO4_F4TeACEBcDxztdwB17_zP0zq60YvgqzzBaw@mail.gmail.com>
--===============1145381060746247696==
Content-Type: multipart/alternative; boundary="0000000000003686ea058b990b7c"

--0000000000003686ea058b990b7c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I'm not an expert, but I found out that if I login as a regular user, I use
sedo only when necessary. But when I login as root (which I do) I am root
all the time. This may cause problems if by mistake I enter a command which
might cause a big damage as root, but not a big damage as a regular user.
Such as, for example, rm -f. So the security issue is also for me entering
as a legitimate user and accidentally writing a wrong command. Which will
probably not happen with sedo. Especially when sedos require for me to
enter my password.

Anyway, some servers I manage I am able to login as root and some not, as
root login there is disabled. I'm not an expert is security but I think
usually my servers are not cracked/hacked as long as I keep the passwords
secure. If I login as root and don't make mistakes such as above, I don't
see why logging in as root is less secure than sedo.

By the way, sometimes I login as a regular user and then su. I don't
remember if this option is enabled in all my servers.
=D7=90=D7=95=D7=A8=D7=99
[email protected]


On Tue, Jun 18, 2019 at 9:24 AM Shlomo Solomon <[email protected]>
wrote:

> This has bothered me for years and I decided to "get it off my chest".
>
> For many years I used su to do administrative tasks, but "everyone"
> uses sudo and the claim is that it's more secure than actually logging
> in as root.
>
> In principal, of course, root login is not a good thing, but let's
> remember something I've never seen discussed. I would assume that on
> most systems the root password is MUCH more secure than that of a
> regular user. Now if I give user david sudo privileges, anyone who
> cracks david's (weak) password now has access to root privileges.
>
> And before anyone says that this is only a one-time authorization, what
> if the guy who cracked david's password now does:
>        sudo passwd root
>
> So what's so secure about using sudo?
>
> --
> Shlomo Solomon
> http://the-solomons.net
> Claws Mail 3.16.0 - Kubuntu 18.04
>
> _______________________________________________
> Linux-il mailing list
> [email protected]
> http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il
>

--0000000000003686ea058b990b7c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I&#39;m not an expert, but I found out that if I login as =
a regular user, I use sedo only when necessary. But when I login as root (w=
hich I do) I am root all the time. This may cause problems if by mistake I =
enter a command which might cause a big damage as root, but not a big damag=
e as a regular user. Such as, for example, rm -f. So the security issue is =
also for me entering as a legitimate user and accidentally writing a wrong =
command. Which will probably not happen with sedo. Especially when sedos re=
quire for me to enter my password.<div><br></div><div>Anyway, some servers =
I manage I am able to login as root and some not, as root login there is di=
sabled. I&#39;m not an expert is security but I think usually my servers ar=
e not cracked/hacked as long as I keep the passwords secure. If I login as =
root and don&#39;t make mistakes such as above, I don&#39;t see why logging=
 in as root is less secure than sedo.</div><div><br></div><div>By the=C2=A0=
way, sometimes I login as a regular user and then su. I don&#39;t remember =
if this option is enabled in all my servers.<br clear=3D"all"><div><div dir=
=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div =
dir=3D"ltr"><div><div dir=3D"ltr"><div style=3D"direction:rtl"><div style=
=3D"direction:rtl">=D7=90=D7=95=D7=A8=D7=99</div><div style=3D"direction:rt=
l"><a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a></=
div></div></div></div></div></div></div><br></div></div><br><div class=3D"g=
mail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Jun 18, 2019 at 9=
:24 AM Shlomo Solomon &lt;<a href=3D"mailto:[email protected]">shlom=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204)=
;padding-left:1ex">This has bothered me for years and I decided to &quot;ge=
t it off my chest&quot;.<br>
<br>
For many years I used su to do administrative tasks, but &quot;everyone&quo=
t;<br>
uses sudo and the claim is that it&#39;s more secure than actually logging<=
br>
in as root. <br>
<br>
In principal, of course, root login is not a good thing, but let&#39;s<br>
remember something I&#39;ve never seen discussed. I would assume that on<br=
>
most systems the root password is MUCH more secure than that of a<br>
regular user. Now if I give user david sudo privileges, anyone who<br>
cracks david&#39;s (weak) password now has access to root privileges. <br>
<br>
And before anyone says that this is only a one-time authorization, what<br>
if the guy who cracked david&#39;s password now does:<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0sudo passwd root<br>
<br>
So what&#39;s so secure about using sudo?=C2=A0 =C2=A0<br>
<br>
-- <br>
Shlomo Solomon<br>
<a href=3D"http://the-solomons.net" rel=3D"noreferrer" target=3D"_blank">ht=
tp://the-solomons.net</a><br>
Claws Mail 3.16.0 - Kubuntu 18.04<br>
<br>
_______________________________________________<br>
Linux-il mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]=
i.ac.il</a><br>
<a href=3D"http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il" rel=3D"n=
oreferrer" target=3D"_blank">http://mailman.cs.huji.ac.il/mailman/listinfo/=
linux-il</a><br>
</blockquote></div>

--0000000000003686ea058b990b7c--


--===============1145381060746247696==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Linux-il mailing list
[email protected]
http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il

--===============1145381060746247696==--