Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even if you allow passwordless su for users in the wheel group?


That's extremely dangerous. Any software running as a wheel user can escalate privileges willy nilly.


they can also access your ssh private keys


In theory, those ssh private keys are password protected.

In practice, maybe not.


They were stored in the user’s yubikeys (or similar) in this example.


If you do that you deserve what you get


Do what!?


plzno




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: