Linked by Thom Holwerda on Wed 31st Mar 2010 14:41 UTC
Thread beginning with comment 416340
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.




Member since:
2009-05-20
'su' doesn't require any group - just that you know the password for that user, root or otherwise.
I don't know which Unix you refer to (probably some weird GNU variant), but this is just plain wrong.
It's only a problem so long as software is designed to require admin rights to function.
My own take on this is that things in Ubuntu (the most popular one, but not the single one, of course) are not that better: a single user is automatically put into the root position. The only thing she needs to do is enter her own password.
It is the same kind of click-click-click -solution than in Windows, downplaying the Unix tradition. But instead of clicking, you type the password. And since we all know how wonderful the concept of password is among the general public ("password123" works in Ubuntu as well as in Facebook and my bank!), it is trivial to exploit.
Edited 2010-04-01 04:51 UTC