Hacker News new | ask | show | jobs
by Nextgrid 1642 days ago
To be fair, if the only thing that the server runs is the application then root or the application’s normal user doesn’t really matter much.
1 comments

It should because if you can exploit the root user, it is much easier to use that machine as a lunching point for a secondary attack. Further, root will let you cover your tracks much more easily than an unprivileged user.