Conficter wrote:
>> Please, how often do I need to hear not to log in as root?
>
> since so many do not seem to know better, and apparently refuse to
> read other posts, old text books, etc etc etc…AND bring with them
> from that “Popular OS” a profound misunderstanding of the how and way
> of *nix system administration: often.
Gee I knew someone would get it wrong and shoot from that angle.
What I am saying is that using “su” from a user account (which which you
IRC, read mail and surf) is just as bad as logging in as root and IRC, read
mail and surf. And I think we all agree that this is something you should
not do.
And I continue to claim:
>> It is not a bad thing in principle.
>
> in principle it is a very bad thing. ymmv
>
>> You’re just not supposed to do your daily work with it.
>> And by the way, using su constantly is not what I call proper privilege
>> separation.
>
> i have no idea how you intend to do administrator tasks without using
> administrator privileges…and, the “separation” is perfect if you
> never ever sign into a GUI as root and always follow the correct
> procedure to use administrator powers…
No, that is NOT perfect separation. CTRL-ALT-F2 is, and so is a new X
session for root if you need it. “su”/“sudo” do not provide that.
>> If you do so, a compromised user account means root is taken
>> as well.
>
> ??? are you saying using “switch user” [su] to become root somehow
> compromises a normal users account? or what?
No. I am saying a compromised user account + “su” means the root account is
compromised.
> ymmv, but your opinion that it is okay to log in as root as long as
> you don’t do your daily work that is wrong.
I beg to differ and I think I have been very clear on why I think so. If
security is a concern, users and root are never to be mixed.
Kind regards,
Andreas Stieger