Full Disclosure mailing list archives
Re: TTY handling when executing code in lower-privileged context (su, virt containers)
From: Michal Zalewski <lcamtuf () coredump cx>
Date: Sun, 11 Nov 2012 09:51:26 -0800
The only thing I am saying is that when you have a choice between direct root logins and using sudo / su, telling people to use the latter option for "security reasons" actually makes them worse off. Poor corporate security practices, schizophrenic account lockout policies, or dealing with "hundreds of administrators" on a single box are completely tangential to that (though you can have as many uid 0 accounts as you want). /mz _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- TTY handling when executing code in lower-privileged context (su, virt containers) halfdog (Nov 10)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Michal Zalewski (Nov 10)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Benji (Nov 10)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Michal Zalewski (Nov 10)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Benji (Nov 10)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Benji (Nov 10)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Jerry Bell (Nov 12)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Michal Zalewski (Nov 11)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Benji (Nov 10)
- Re: TTY handling when executing code in lower-privileged context (su, virt containers) Michal Zalewski (Nov 10)
