Security of using sudo rather than su?

Tony Arnold tony.arnold at manchester.ac.uk
Fri Sep 15 13:45:12 UTC 2006


On Fri, 2006-09-15 at 14:24 +0100, Adam Funk wrote:
> On 2006-09-15, Derek Broughton <news at pointerstop.ca> wrote:
> 
> > This is the real problem (the diligent ones put the post-it on the bottom of
> > their keyboard).  Everybody figures that it would take too long to get
> > support to reset their password, or they're just too embarrassed to ask
> > (especially if they think the tech support will actually look and find the
> > password they've forgotten, because it's almost always too cute or too
> > rude!).
> 
> That's the real reason *n*x systems store and compare encrypted
> passwords: so you can't tell that they're rude in plaintext.

The ruder the better; less chance of the user sharing it with somebody!

Regards,
Tony.
-- 
Tony Arnold, IT Security Coordinator, University of Manchester,
IT Services Division, Kilburn Building, Oxford Road, Manchester M13 9PL.
T: +44 (0)161 275 6093, F: +44 (0)870 136 1004, M: +44 (0)773 330 0039
E: tony.arnold at manchester.ac.uk, H: http://www.man.ac.uk/Tony.Arnold





More information about the ubuntu-users mailing list