Subject: Re: getpwent(3) funcs return static structure (fwd)
To: None <current-users@NetBSD.ORG>
From: Iain Hibbert <plunky@skate.demon.co.uk>
List: current-users
Date: 03/14/1997 13:54:54
On Thu, 13 Mar 1997, Greg A. Woods wrote:

> Multiple accounts with uid==0 in the password file are a bad idea, from
> a security perspective.  They increase the risk of a successful root
> attack quite a bit (by an order of N^2 possibly?).

I'm unclear as to why we should be encouraging more than one user per uid at
all..  I thought that was the point of uid's, that they were unique, though
maybe this limits the number of users too much? 

maybe we should include sudo in the source tree for allowing people other 
than root to do admin tasks?

iain