3 ms·
Ah, yes, those BSD idiots with their root and toor accounts, clearly clueless about security concerns. I don’t recall ever seeing a security requirement not to
by kstrauser 2mo ago
Ah, yes, those BSD idiots with their root and toor accounts, clearly clueless about security concerns.
I don’t recall ever seeing a security requirement not to have 2 root accounts. What you can’t have is multiple users sharing the same account. This is different.
- ffsm8 2mo agoin case anyone else is mildly curious (i didnt know that was a thing) > The reason it exists is shell flexibility. Traditionally root's shell is kept as a statically-linked shell like /bin/csh or /bin/sh so that the superuser can always log in even in single-user mode or if dynamically-linked shells in /usr/local break. The toor account lets an admin have a UID 0 login with a fancier daily-driver shell (bash, zsh, etc.) without touching root's safe configuration.
- kazinator 2mo agoIt is different when it is a well-known thing. If you see "toor" in a BSD password file, you know that's a BSD thing and not someone making a backdoor. I'm wildly guessing that the BSD flavors that have toor have patched their password DB manipulation utilities and APIs such that when you change the root password, the toor one changes with it and vice versa.