Reply to post: Re: Pro Tip

Microsoft drops rush Internet Explorer fix for remote code exec hole

Richard Plinston

Re: Pro Tip

> We now have sudo attempting to do much the same thing but all too often set up to simply use the user's own password rather than root's and to be as omnipotent as root in terms of privilege.

On a desktop machine owned and used by just one user, at home for example, then admin being done using sudo is appropriate - there is no administrator other than that user.

On other machines where there is a separate administrator then the sudo is easily controlled as to what each user can actually do (see /etc/sudoers file, if you are allowed to). They can also be given permission to do stuff or access stuff by making them members of a particular group and giving permission to the group.

> For instance a user logged in as the printer administrator could administer the printing sub-system to stop & start queues etc without having root access.

They don't have to login as a specific user (though it could be done that way), Access can be given to a specific group and particular users can be added to that group. (A user can be a member of several groups).

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon