You wrote "the standard 'wizard' ". Do other distros autocreate a user
named 'wizard', or expect the sysadmin to create one if needed? Also,
why not create a *group* named 'wizard' instead?

P.S. Should priority on this bug be bumped to, say, normal? I see no
reason why users who want to run nethack in wizard mode should have to
expose their systems even to a minuscule risk of data corruption. As
the Security section of the Release Critical Issues for Etch document
says: "Programs must be setup to use the minimum privleges they can.
(ie, not setuid where setgid will suffice; not setuid root where
setuid some other user will suffice; setuid root for the minimum
period possible, etc)". (http://release.debian.org/etch_rc_policy.txt)
Yet this bug only forces users to run nethack as root if they want to
use wizard mode, not for the rest of the game's functionality, so it's
not as bad.

Reply via email to