DE version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
33% Positive
Analyzed from 666 words in the discussion.
Trending Topics
#root#personal#user#non#don#things#access#data#try#read

Discussion (16 Comments)Read Original on HackerNews
For one, as non-root user you are tied to the permissions system and can't access most of the data. If one of your services (let's say sql) get hacked, they are tied to sql user, and unless the achieve privilege escalation, they can't mangle with other services data (eg webserver).
Also network wide, a non-root user can't use different protocol than tcp and udp. The only reason you can ping as a regular user is because of the setuid on the ping program, otherwise icmp is not allowed to non-root users.
There are of course other reasons, but these are some examples on how it would be different.
With root, I can read all program memory, try to extract decryption keys for encrypted filesystems, modify the kernel, punch open backdoors, modify any arbitrary program, read all user files, etc.
A notable extra issue is the rise of AI agents, which often eagerly test the boundaries of every sandbox they are placed within. I would not run an AI agent as root, nor would I give it full access to a rootful container runtime.
Are people really terminally online enough to understand this?
OpenMandriva would be my next guess, but it's not a newer distro.
A blog post talking about security but refusing to mention which operating was vulnerable to an exploit out of virtue signaling(?) is absurdist comedy.
If the author is referring to Omarchy, should we also stop using and mentioning Ruby on Rails? Preposterous.