Thoughts about running as root
Marvin GodfatherofSoul Bellamy
mbellamy at kc.rr.com
Fri Aug 30 19:49:20 CDT 2002
Some tasks like web browsing will be pretty dangerous as root. Think of
all the executables that Yoos R. Stoopid downloads and fires off without
hesitation on a Windows box. If you've got people doing that on a UNIX
box as root, you have completely negated the security advantages of a
true multiuser OS.
"Hey, kids! Here's a cool game! Just download it and run it and HAVE FUN!"
or
"Hot teen action. Download this file and run it to get your free
Brittney Spears pics!!"
...
#!/bin/sh
rm -rf /
...
Jason Clinton wrote:
> Jonathan Hutchins wrote:
>
>> Ever since I started messing with Linux, there's been this conflict.
>> All
>> the experienced gurus, authors, and pundits strictly advise against
>> running
>> as root. With a new install, especially of the older distributions, you
>> can't do squat except as root. Even now, most of my time in Linux is
>> not
>> spent in userland, but working on the system.
>>
>> As with the "warning" on editing your crontab, though, I think this is a
>> spurious caution. Most of the "errors" that they warn you about are
>> errors
>> that would only be made by someone with a good deal of experience
>> running
>> Linux as a user. For instance, I've never issued "rm -r *" or it's
>> deadly
>> variants in years of use.
>>
>> It may be that having come from a system-level environment, either
>> running
>> DOS on PC's or running JCL and system management on mainframes, I'm more
>> aware of what I'm doing. Or it may just be that the habits I've
>> built up in
>> Linux are based on the fact that I'm root, and I know I can affect the
>> system if I don't pay attention.
>>
>> So while it's fairly dangerous for someone with a lot of Unix user
>> experience to run Linux as root, for me it's no worse than running
>> DOS as
>> ... well, running DOS.
>>
>>
> A recent (May) Ask Slashdot on the subject:
> http://apple.slashdot.org/article.pl?sid=02/05/06/0348213&mode=thread&tid=179
>
>
> A funny quote from a poster in that article:
> "Root is like crack"
> "Don't smoke it. I did once and got hooked. I ran Mac OS Updates as
> root. Fuck, I even had sex with my girlfriend as root. Man, that
> caused some permissions problems. When I started the road to recovery
> (logging in as Zacks) my girlfriend was all like: "Fuck no! You can't
> get any cause you don't own me an I don't go groups. You don't have
> the power to read, write OR execute so get out of my FACE" So I was
> all HELL NO bitch. And she wuz like you do not have root (superuser)
> privlages so get out of my TruBlueEnvironment! So then I went chown
> and chmodded her ass to me. Dat be-otch be up in my hizzouse. What
> what. Holla!"
>
More information about the Kclug
mailing list