Nor will sudo protect you from blindly typing in your root passwo…

Nor will sudo protect you from blindly typing in your root password. UAC does demand an administrator users credentials if you are not an administrator, so there is no difference there.

http://en.wikipedia.org/wiki/Image:User_Account_Co …

The Achilles heel of both is that they require the thing between the keyboard and chair to exercise reasonable judgment, to ask themselves whether that process really needs to be playing with system files. But as I said, NTFS has proper user proper user rights. A local privilege escalation requires an elevate process to be compromised; could happen of course, but so it also could on any OS that uses sudo (or runas under windows).

The *nix trick Redmond finally started to learn was to only give the user additional privileges if they actually need them to do the current task.

Leave a Reply