That's very sensible, I wonder why it's not the default setup everywhere.
That's very sensible, I wonder why it's not the default setup everywhere.
If the package was set up to install /usr/bin/sudo so it was only runnable by members of the wheel group, that wouldn't work.
[0] https://web.archive.org/web/20070603191229/http://www.gnu.or...
Hell, not even GNU distros like GNU Guix, Parabola, nor Trisquel follow RMS' opinions on this anymore.
I have used sudo a lot of times to allow a specific user to run exactly one command with elevated rights. In those cases they weren't in the wheel group.
If you are really thinking security, elevating a standard user seems bad practice to anyways. It is rather I guess a way to protect the user to do `rm -rf /` accidentally. On the other end adding an another layer of obscurity is practically adding a bit of security against script kiddies. But if that is of concern one could also rename the sudo binary.
One last thing the SSH trick might be interesting is the portability but in this case I would rather go via a standard TCP socket.