Hacker News new | ask | show | jobs
by KenoFischer 2700 days ago
FWIW, in my experience there's lots of middle ground between the host being completely untrusted and the user having root on both the host and the BMC. Anywhere from "we're letting random third party collaborators share our machines" to "it's only in-house users, but they may not properly secure their machines" is a use case where regular users even with root on the host would not have root on the BMC.