|
|
|
|
|
by cperciva
1029 days ago
|
|
What is special about the 'wheel' group and what is su even "checking" in the first place? Users who aren't in the wheel group aren't supposed to be able to become root, even if they have the password. Isn't it just supposed to switch user? And what are the implications of not-checking whatever it was supposed to check? Someone who steals the root password (say, by looking over the sysadmin's shoulder) would be able to become root. And I also don't get: if someone has the root password, can't they change what groups they're a member of? No, because they can't log in as root and (on non-broken systems) can't become root. |
|
Or is the wheel group not really about being able to sudo?