Members of the sudo group in my Debian install can execute anything without entering a password. This is convenient, but seems like a bad idea.
NOTE: My computer is an ordinary desktop, not a server or something like that.
Should I disable this or is it safe?
Bonus points for explaining what could happen (i.e. possible attack vectors).









