3 ms·
If setting a root password is a hack, I'm Donald Duck.
by 5ilv3r 9y ago
If setting a root password is a hack, I'm Donald Duck.
- saagarjha 9y agoI really can't respond to you unless you explain your reasoning…
- snowpalmer 9y agoI assume he means that you should always set a password for "root". Though most users don't even knows it exists.. hence it should have been taken care of by apple.
- 5ilv3r 9y agoNo, not always. I just mean that sudo is a (very very popular) hack.
- 5ilv3r 9y agoUhg, ok I forgot some people don't know the code. The old adage is "On your first day as the new sysadmin, change all the root passwords". The idea is that a SECURE root is good, possibly better than no root (which is sort of a hack in itself). There are best practices for root passwords. Things like length, composition (no dict words), disabled for remote access, and care in who is allowed to have it. Simply pretending root does not exist is a rather new idea and is not best practice. It's only for convenience.
- saagarjha 9y ago> Simply pretending root does not exist is a rather new idea and is not best practice. It's only for convenience. Says who? Sure, it's convenient not to have to worry about choosing a secure password for your root account, but why is it "sort of a hack in itself"?
- Forbo 9y ago> composition (no dict words), This is an outmoded guideline for password security. String enough dictionary words together and you achieve a high level of entropy. See for example https://en.wikipedia.org/wiki/Diceware https://en.wikipedia.org/wiki/Diceware