sudo security concerns ?

Matt Zimmerman mdz at canonical.com
Sat Nov 27 21:40:18 CST 2004


On Fri, Nov 26, 2004 at 01:08:45PM -0800, Karl Hegbloom wrote:

> At the very least, this issue should be documented in the manuals.  Warn
> users not to do that.  Explain the possibility, tell them not to do
> that.

A manual which documented everythin that users should avoid doing for
security reasons would be long indeed.

> Security through obscurity is not going to prevent the inevitable.

Fortunately, we rely on real security measures, and not obscurity, in
Ubuntu.

> This situation with Sudo looks to me like a relatively easy target
> to hit...

This has been discussed to death, and I've added some additional text to the
RootSudo page in the wiki to hopefully avoid further confusion.

-- 
 - mdz



More information about the ubuntu-devel mailing list