Re: dangerous to leave root logged in?

hans_schulze98_at_yahoo.de
Date: 03/28/05


Date: 28 Mar 2005 13:08:56 -0800


prg wrote:
> hans_schulze98@yahoo.de wrote:
> > Is it a problem to leave root logged in at all times?
>
> Yes. That is "Yes". And in case you did not get it, "YES".
>
> > ... Or to leave
> > root-admin tools (YaST, kuser, ...) running at all times? ...
>
> See above!

I appreciate if people tell me about specific problems with this setup
(as opposed to the commonly-asked question whether you should log in as
root
*and* use it for everyday activities).

> > ... This is done
> > on a different X Server than the ones used
> > for regular users, and noone has physical access to the machine
(but
> > internet is always on).
>
> Run _anything_ as root as little as possible, for as short a time as
> possible.

But maybe this is safer? No root passwd to type within normal user's
account.

> > In fact, is it dangerous to run an (extra) X-server for root
> > (additionally to the one for the
> > user)? E.g. SUSE prevents this; logging root into kdm only gives
> YaST,
> > not KDE.
>
> SuSe is trying to protect you from yourself ;-)

Not if permissions are "easy" or "normal".

> If you want convenience (laziness?), use Windows. What's the point
of
> subverting the security mechanisms built into *nix?

What? Under *nix, X always runs as root, no matter what you try. For
every user.

> Root priviledges are sometimes _necessary_ but should be (and usually
> are) dropped as quickly as possible by applications.

So what's the problem with an idle root-xterm? Where's the risk? It
just sits there.

> Applications that _run_ as root (eg., config tools) for their
duration
> are _not_, _not_, _absolutely_not_ to be left "hanging around" for
your
> convenience (ie., laziness). Invoke them, use them, then close them.
> Period.

Strong convictions like this require reasons.



Relevant Pages

  • Re: Virus/Spywaare
    ... Another reason is that a virus under *nix just doesn't go anywhere. ... The method by which users login to *nix systems is to be a regular user. ... You almost never have to login as root. ... To format a floppy, use "fdformat /dev/fd0" ...
    (alt.os.linux.suse)
  • Re: unix and email viruses
    ... I only run 'nix (debian, OpenBSD), and I'm on dialup. ... can break e.g. mutt that mutt will be fixed around the same time as a ... don't read email as root. ...
    (Debian-User)
  • Re: Suse 11.1 cant join my Apple Wireless Network.
    ... Vahis wrote: ... I thought it is kind of a *nix, ... It's based on BSD ... You can get a root prompt by doing 'sudo su -' like Ubuntu, ...
    (alt.os.linux.suse)
  • Re: FC5 Gnome progress
    ... You should not be running Gnome as root long enough to ... Root is reserved for special operations. ... The trend today in *nix is to disable root account, ...
    (Fedora)
  • Re: Setting password policy on Solaris 8/9
    ... > Looks like we will start with PASSLENGTH setting for regular users and ... > look into possibilities to restrict root somehow. ... The problem with "restricting root" is that you really can't, ... that's paged when you need to real root password. ...
    (comp.unix.solaris)