should defaults be secure or convenient?

As with most questions like that, the real answer is “it depends”

Updating a Debian (sarge) box today, I was still a little surprised at the phrase “if in doubt … install it with SUID”.  Is the subset of sites running host-based auth and *not* sure about whether to install suid really worth having an insecure (at least from a defense-in-depth POV) default?  Clearly a subjective question.


