3 ms·
Uhg, ok I forgot some people don't know the code. The old adage is "On your first day as the new sysadmin, change all the root passwords". The idea is that a SE
by 5ilv3r 9y ago
Uhg, ok I forgot some people don't know the code. The old adage is "On your first day as the new sysadmin, change all the root passwords". The idea is that a SECURE root is good, possibly better than no root (which is sort of a hack in itself). There are best practices for root passwords. Things like length, composition (no dict words), disabled for remote access, and care in who is allowed to have it.
Simply pretending root does not exist is a rather new idea and is not best practice. It's only for convenience.
- saagarjha 9y ago> Simply pretending root does not exist is a rather new idea and is not best practice. It's only for convenience. Says who? Sure, it's convenient not to have to worry about choosing a secure password for your root account, but why is it "sort of a hack in itself"?
- Forbo 9y ago> composition (no dict words), This is an outmoded guideline for password security. String enough dictionary words together and you achieve a high level of entropy. See for example https://en.wikipedia.org/wiki/Diceware https://en.wikipedia.org/wiki/Diceware