linux """"""""""""""""""""""""""""""""security""""""""""""""""""""""""""""""""

> linux """"""""""""""""""""""""""""""""security""""""""""""""""""""""""""""""""

200 replies, 14 images (click to view thread)

> implyin

Why not?
im up for memeing.

>"sudo make me a sandwich"
>Password:
There, fixed.

>[sudo] Password for root:

>he thinks that because his user is in wheel literally every user is

Sudo only allows whoever is in the sudoers file to run commands as root. It also asks you for your password by default. The administrator can also set sudo so it only works on a few commands on a per user basis

But what's to stop the administrator from fucking up the system?

Fucking nothing but that's not the system's fault, that's admin error and the thread doesn't make an attempt at criticizing that so it's off-topic in the context of this thread and the same security error of humans is present in any system humans have ever touched.

Everyone recommends a """security layer""" developed by the NSA.

/thread

Active Directory

What is /etc/sudoers for 1,000,000,000 please.

>computers suck when their users suck!
stop the presses

You can just not add dangerous commands there.

Absolutely nothing, and that's a good thing. Good security follows what is known as the CIA model:

Confidentiality -- Data is inaccessible to those without authorization.
Integrity -- Data is accurate and consistent over its lifecycle (can't be tampered with, at least not by those without authorization).
Availability -- Data is accessible to all with authorization.

If administrators were not allowed to do whatever they wanted, one would have confidentiality, but not availability. This is no good. The best security ensures that only the individual with the root password is capable of ever obtaining root. After that, it is solely the responsibility of the user to ensure that this password does not fall into the wrong hands.

If the one person who has root access wrecks the system their boss would probably fire them.

SELinux is used just for that scenario.

sudo isnt required.

dont be a scrub ob.

>muh walled garden
Stick to mac shit