sudo and secure-path

Jon Stanley jonstanley at gmail.com
Wed Nov 19 02:23:50 UTC 2008


On Tue, Nov 18, 2008 at 8:54 PM, Matthew Miller <mattdm at mattdm.org> wrote:

> Yes. The tab-completion thing working is a side-effect -- the more important
> thing is no surprises. How about a compromise -- add /usr/local/sbin to the
> secure path?

You can't be guaranteed that path is in fact secure. Lots of systems
mount /usr/local from somewhere outside of their domain of control,
and I don't want to blindly trust stuff in there.

Users have a PATH for a reason. Let them keep it.




More information about the devel mailing list