Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 9 Jul 1996 19:35:18 -0700 (PDT)
From:      batie@agora.rdrop.com (Alan Batie)
To:        phowlett@ASG.unb.ca (Peter Howlett)
Cc:        taob@io.org, freebsd-security@freebsd.org
Subject:   Re: sudo
Message-ID:  <m0udp7X-0008s7C@agora.rdrop.com>
In-Reply-To: <Pine.A32.3.93.960709214758.14947A-100000@angus.ASG.unb.ca> from "Peter Howlett" at Jul 9, 96 10:11:54 pm

next in thread | previous in thread | raw e-mail | index | archive | help
> We use sudo here at the office. It can be useful, but you do have
> to be _very_ careful with it.

To expand a little on my earlier terse comment :-)

I only allow access to it for people I trust as root users; one is
allowed to run a script that creates a particular class of users,
and I think it's secure, but even so it's someone I trust.  The
thing I don't trust is my ability to be certain that a program doesn't
have back doors in it.

The reason I call it indispensable is because I use it all the time.
I get dozens of 5-second root-only requests/interrupts/things-that-need-done
a day, and the other option is having a root window open all the time, and
even that's not as convenient.

-- 
Alan Batie                   ______      We're Starfleet officers:
batie@agora.rdrop.com        \    /      Weird is part of the job.
+1 503 452-0960               \  /       --Captain Janeway
DE 3C 29 17 C0 49 7A 27        \/        40 A5 3C 37 4A DA 52 B9

It is my policy to avoid purchase of any products from companies which
use unrequested email advertisements or telephone solicitation.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?m0udp7X-0008s7C>