Hacker News new | ask | show | jobs
by 65a 1967 days ago
It is almost always the case that a sufficiently malicious user can find a way to turn that into full blown root access.
1 comments

So that means they should get full blown root from the beginning?
IMHO yes because then you treat the access with the gravity that is required.