On Thu, 2004-11-25 at 20:00 -0800, Karl Hegbloom wrote:

> Can a program or script running under my own UID monitor keystrokes and
> learn my sudo password?
Sure, also if you run a root shell inside a terminal running as your own
UID then if your account is compromised they can inject key-strokes into
it and do things as root.

Ever read Terry Pratchett?  If so you know that whenever Wizards use
magic, the evil beings from the Dungeon Dimensions appear and try to
break into our world ...  It's like that every time you "become root",
you open up a doorway to evil.

