logoalt Hacker News

direwolf20today at 12:19 AM2 repliesview on HN

Literally how else is a remote login daemon supposed to work though?


Replies

dragonfaxtoday at 12:22 AM

1. Start with root to bind the port below 1024.

2. give up root because you don't need it any further.

3. Only accept non-root logins

4. when a user creates a session, if they need root within the session they can obtain it via sudo or su.

show 7 replies
charcircuittoday at 12:32 AM

The remote daemon has its own account and is given a privilege that allows it to connect a network socket to a pseudo terminal.

show 2 replies