There is no debate about this. It is insecure and irresponsible for xscreensaver-auth to *not* be setuid root.
Install it setuid root, as it was designed to be, and as "make install" does by default.
There is no debate about this. It is insecure and irresponsible for xscreensaver-auth to *not* be setuid root.
Install it setuid root, as it was designed to be, and as "make install" does by default.