Hacker News new | ask | show | jobs
by akira2501 719 days ago
Even if you allow passwordless su for users in the wheel group?
4 comments

That's extremely dangerous. Any software running as a wheel user can escalate privileges willy nilly.
they can also access your ssh private keys
In theory, those ssh private keys are password protected.

In practice, maybe not.

They were stored in the user’s yubikeys (or similar) in this example.
If you do that you deserve what you get
Do what!?
plzno