4 ms·
If you're using sudo, then the root password is irrelevant; it's the local users password that elevates permissions. I see this as both good and bad - users sh
by BuildTheRobots 5y ago
If you're using sudo, then the root password is irrelevant; it's the local users password that elevates permissions.
I see this as both good and bad - users should know their own private credential (rather than the shared "secret" root passwd), but as it's a password they use regularly (potentially multiple times a day), it's easy for people to use something less secure than they otherwise would for "root".
- znpy 5y ago> If you're using sudo, then the root password is irrelevant This is very true, but I'd also like to add that getting root privileges might not even be that important. You only need privileges for the user owning the data. You might not get to root, but you can still do a fair amount of stuff with non-root.
- LinuxBender 5y agoUnrestricted sudo is certainly dangerous. The scripts I have used in the past to test for passwordless sudo call sudo -n It's a nice way to see if you can run commands as root with nothing more than getting someone to execute a script. To my surprise it turns out about 10% of an organization will do just that.
- BuildTheRobots 5y agoTo be honest, I was more thinking that if it's your desktop or user password, then it's likely to be easily typeable (people unlock their laptops multiple times a day), compared to an occasionally copy/pasted password from a safe. I didn't even think about passwordless sudo :)
- LinuxBender 5y agoPasswordless sudo + SSH Multiplexing negate the need for any back doors at the end of the day. As a bonus, anti-malware software will never detect or report on using ssh and sudo. Combine those with some obfuscation tools likely already installed on the victims machine called by a python or shell script and you can walk in the front door of just about any organization on earth.