@emil sure, that definitely increases attack surface

but this issue made me realize i don't particularly need a 'run as root' command, for the rare things i need to do system-wide i can just login as root

@orionwl @emil isn't allowing root login considered a security bad practice also?

@kekcoin @emil i think that's a leftover from the time that brute forcing passwords was a thing

i never use ssh password based authentication at all (always keys, stored on external token when possible)

locally, logging in as root with a password seems fine

Follow

@orionwl @kekcoin @emil@x0f.org On Qubes, sudo doesn't require a password at all. Good document describing why: qubes-os.org/doc/vm-sudo/

Kinda a meta version of your "don't need a 'run as root'" argument!

· · Web · 1 · 0 · 5

@pete @orionwl @emil Well, that argument only holds in that specific usecase. Also PolKit isn't to blame for X11's flaws, right?

Sign in to participate in the conversation
Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!