Fedora to (try to) remove setuid files for F15
Fedora to (try to) remove setuid files for F15
Posted Nov 8, 2010 8:48 UTC (Mon) by solardiz (guest, #35993)In reply to: Fedora to (try to) remove setuid files for F15 by dlang
Parent article: Fedora to (try to) remove setuid files for F15
No extra passwords and no extra accounts to manage. It would be a security risk for a sysadmin to share a non-root account for su'ing to root and for other uses (a lot of people do just that, but it's plain wrong to take the unjustified risk, in my opinion). Thus, there would have to be _two_ non-root accounts per person. With our approach, this is replaced with one root-privileged account and one non-root account. (Also, SSH keys are used instead of passwords in most cases. And it is OK to use the same keypair for root and non-root.)
