Zack Weinberg on Nostr: 2. Closely related to 1: If you can swing it such that root is the _only_ account ...
2. Closely related to 1: If you can swing it such that root is the _only_ account that's unlocked for shell access -- every other account has a locked password and '/usr/sbin/nologin' for its shell -- that also makes privilege escalation significantly harder.