Skip to content

Comment on The OpenSSH Bug That Wasn'tparent

Comments

From an accountability standpoint, if each person logs in to the root account directly with a distinct private/public key, you can still have full individual accountability.

I'd think the complexity side of the sudo strategy is self-evident, so perhaps I'm not understanding the part that needs explaining.

I don't find 'sudo' to be complex at all. If in your situation I would have had the ability to log in as root, in my situation I will be in the 'wheel' group. It seems very straightforward to me.

I think you misunderstand my point. You have increased the complexity of securing the system. You now have each user's login shells, all of the joys of what those login shells touch, the sudo program and its configuration, all added to the attack surface.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.