Re: sudo without password
- From: "Michael T. Richter" <ttmrichter@xxxxxxxxx>
- Date: Wed, 07 Jun 2006 14:28:28 +0800
On Wed, 2006-07-06 at 02:04 -0400, Scott Kitterman wrote:
Note that doing this is a very bad idea from a security standpoint....
And none of this makes the slightest difference to the well-being of the
single most important stuff on your computer: Your own files.
So.............. a 'very bad idea from a security standpoint'... hardly.
This is a point that seems to be missed in the UNIX community a lot: the
vast majority of computer users no longer run on time-shared, multi-user
systems. "Security" is "me and my files" not "my system because if it
goes down hundreds of others are inconvenienced".
It's a different world. UNIX will catch up sometime.
If I screw up and make my data available to someone, that hurts me.
And that is the most common security exploit even under Windows. You
lose your data. We just hear about the other ones more because a)
they're the scary ones and sensationalism always wins out over numbers
and b) they're the ones that we're more likely to see in the wild when
they hit (by their very nature).
If I screw up and compromise my machine and give it over to some
spammer/phisher/[insert favorite net crime here], then I've hurt the entire
internet.
How nicely full of hubris. "My little laptop will bring down the
Internet."
Tragically, however, the worst attacks ever only brought down a part of
the Internet for small periods of time (relatively speaking).
It's a different world. UNIX was designed for it.
UNIX was designed long before there was an Internet. And its security
model shows it. (Sudo is an afterthought, not the primary model.) A
modern security model would be capabilities-based -- you know, two
generations of security architecture past what UNIX was designed with.
--
Michael T. Richter
Email: ttmrichter@xxxxxxxxx, mtr1966@xxxxxxxxxx
MSN: ttmrichter@xxxxxxxxxxx, mtr1966@xxxxxxxxxxx; YIM:
michael_richter_1966; AIM: YanJiahua1966; ICQ: 241960658; Jabber:
mtr1966@xxxxxxxxx
"My paramount object in this struggle is to save the Union, and is not
either to save or to destroy slavery." --Abraham Lincoln
Attachment:
signature.asc
Description: This is a digitally signed message part
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
https://lists.ubuntu.com/mailman/listinfo/ubuntu-users
- Follow-Ups:
- Re: sudo without password
- From: Morten W. J.
- Re: sudo without password
- From: Alan McKinnon
- Re: sudo without password
- From: Scott Kitterman
- Re: sudo without password
- From: Adriano Varoli Piazza
- Re: sudo without password
- References:
- sudo without password
- From: Mladen Bestvina
- Re: sudo without password
- From: Chanchao
- Re: sudo without password
- From: Michael T. Richter
- Re: sudo without password
- From: Scott Kitterman
- sudo without password
- Prev by Date: Re: dapper freeze
- Next by Date: Re: Dual cores not showing with kernel-686
- Previous by thread: Re: sudo without password
- Next by thread: Re: sudo without password
- Index(es):
Relevant Pages
|