Comment Re:Note that this is a local exploit (Score 4, Informative) 138
I hate how this reasoning persists. It is just so disconnected from the real world.
So should large organizations just not bother with least privilege and normal users? Everyone might as well be root, if one with bad intentions gets access to a system, well they should be assumed to just be root anyways?
I mean, in a company with even 100 people, if one of their accounts gets compromised, or one of them goes rogue, "you have already messed up" really isn't the point. I used to run a data ingest system where we gave limited shell accounts to somewhere around 1,000 clients, plenty of similar but much larger systems are out there. No one *at my company* had messed up in any way if one of those accounts went rogue. Tons of systems like that exist, it's not some edge case.