Path: utzoo!attcan!utgpu!jarvis.csri.toronto.edu!mailrus!ames!haven!adm!smoke!gwyn From: gwyn@smoke.BRL.MIL (Doug Gwyn) Newsgroups: comp.unix.wizards Subject: Re: Multiple Root ID's considered evil? Message-ID: <11041@smoke.BRL.MIL> Date: 12 Sep 89 17:03:45 GMT References: <1723@convex.UUCP> <11038@smoke.BRL.MIL> <89Sep12.115240edt.2385@neat.cs.toronto.edu> Reply-To: gwyn@brl.arpa (Doug Gwyn) Organization: Ballistic Research Lab (BRL), APG, MD. Lines: 7 In article <89Sep12.115240edt.2385@neat.cs.toronto.edu> rayan@cs.toronto.edu (Rayan Zachariassen) writes: >We did start out with most of our binaries owned by a non-0 id for >ideological reasons, but quickly reverted to root ownership because of >these problems. It is easier to firewall root than a zoo of other ids. Yes, but the idea is to have a set-UID (0 in this case) program for installing the software, not to turn loose humans with elevated permissions.