The sudo fraud
ilya-sher.org
ilya-sher.org
every command you run with sudo is logged, along with the user than ran it. On GCP each end user is provisioned a separate login user, and logs can be shipped to Stackdriver Logging where they cannot be modified. This makes access really verifiable.
Yeesh. Privileged work I do is typically interleaved with commands that do not need to be privileged. Actual security considerations aside, I would rather have the guard rails afforded me by a normal user account for things that don't have some specific reason to be privileged.
red = root
yellow = others (or ssh)
green = me
Plus when I'm SSH'ing to a remote box, it usually defaults to white promptJust to be clear: Please note it’s filed under the “Rant” category. The post has some valid points but don’t take it too seriously. Use your best judgment to decide which parts of the above apply to your situation. ===8<===