MESSAGE
DATE | 2003-03-05 |
FROM | Ron Guerin
|
SUBJECT | Re: [hangout] bash history
|
On Wed, 2003-03-05 at 12:07, Marco Scoffier wrote: > On Wed, Mar 05, 2003 at 11:01:49AM -0500, Ruben Safir wrote: > > > > what's the pros and cons of having the root history around. > > > Well it is one of the most obvious places to look for passwords. > > su password > > is quite a common mistake. as is ssh user-at-host password > > I don't erase root's history in fact I am a huge fan of history. I love > that the long complex command I typed in last week or three weeks ago is > still lying around. I believe Jay thinks strongly about this also.
Unfortunately, it is both. A wonderful convenience and a foolish security risk. I'm about to delete my MySQL history because I know it's the right thing to do from a security standpoint, while knowing I'll miss it when it's gone.
The trick for that is to maintain a little file with those complex commands. I don't remember to add to it as often as I should though.
- Ron
____________________________ NYLXS: New Yorker Free Software Users Scene Fair Use - because it's either fair use or useless.... NYLXS is a trademark of NYLXS, Inc
|
|