But naturally it happens all the time! That's what i love about computer security when ever you try to tell someone to do something normal and smart they do the polar opposite =)<br><br>
<div><span class="gmail_quote">On 2/4/07, <b class="gmail_sendername">Q-Ball</b> <<a href="mailto:qballus@gmail.com">qballus@gmail.com</a>> wrote:</span>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">On 2/2/07, <a href="mailto:Valdis.Kletnieks@vt.edu">Valdis.Kletnieks@vt.edu</a> <<a href="mailto:Valdis.Kletnieks@vt.edu">
Valdis.Kletnieks@vt.edu</a>> wrote:<br>> On Fri, 02 Feb 2007 13:40:47 +0530, Raj Mathur said:<br>> > I believe we have had this discussion before, but I'll iterate my<br>> > beliefs in favour of allowing direct root access again:
<br>><br>> > - Key-based root logins are quite secure. I don't see any reason why<br>> > key-based root login would be any less secure than permitting a user<br>> > login followed by an sudo.<br>
><br>> It's not the security of the login itself - it's the ability to create<br>> an audit trail of which userid performed an action. If you can find<br>> some other way to...<br>><br><br>Yes ability to audit is important, and you can still retain
<br>accountably with direct root logons depending upon configuration but<br>there are two major security problems<br>with direct root logons:<br>- Remote brute forcing. Personally I'd rather someone crack 2 accounts<br>
rather than just one, but maybe that's just me ;-)<br>- Security should be implemented on a least privilege basis. Logging<br>on as root as opposed to a user, isn't always required and just<br>increases your window of opportunity eg. SSH channel attacks, key
<br>loggers, brute forcing, etc.Quite often sudo should suffice for<br>regular tasks.<br><br>_______________________________________________<br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">
http://lists.grok.org.uk/full-disclosure-charter.html</a><br>Hosted and sponsored by Secunia - <a href="http://secunia.com/">http://secunia.com/</a><br></blockquote></div><br><br clear="all"><br>-- <br><a href="http://www.goldwatches.com">
http://www.goldwatches.com</a><br><a href="http://www.wazoozle.com">http://www.wazoozle.com</a>