Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Linux

Kali Linux will no longer use root account by default

by Nam Phong · January 6, 2020

The Kali Linux operating system, which is very well-known in the security industry, has released a version update announcement. If there is no accident, the project team will release the Kali Linux 2020.1 update later this month. It is also from this version that the operating system will no longer use the root account by default, and switch to the new security model.

The Kali Linux project team said: “As part of our evaluation of Kali tools and policies we have decided to change this and move Kali to a “traditional default non-root user” model. This change will be part of the 2020.1 release, currently scheduled for late January. However, you will notice this change in the weekly images starting now.”

Kali Linux Raspberry Pi 4

Image: kali

The overall stability of Kali Linux has been getting higher and higher, which has also made more and more users use this operating system as the main operating system, although researchers or ordinary users are not encouraged to use Kali as the main operating system. But more and more users have indeed done so in the past few years, and their main use may not be penetration and security testing.

When people use Kali as the main operating system, they obviously do not need to run the root account, because most software and tools do not require root permissions. For this reason, the project team decided to change the security model in accordance with user needs. The root account is no longer the default account.

Next, Kali will guide the user to create a non-root account with administrator privileges for daily use during the installation phase. Of course, if the user needs root privileges, he can still switch to root privileges.

• Kali in live mode will be running as user kali password kali. No more root/toor. (Get ready to set up your IDS filters, as we are sure this user/pass combo will be being scanned for by bots everywhere soon).
• On install, Kali will prompt you to create a non-root user that will have administrative privileges (due to its addition to the sudo group). This is the same process as other Linux distros you may be familiar with.
• Tools that we identify as needing root access, as well as common administrative functions such as starting/stopping services, will interactively ask for administrative privileges (at least when started from the Kali menu). If you really don’t care about security, and if you prefer the old model, you can install kali-grant-root and run dpkg-reconfigure kali-grant-root to configure password-less root rights.

Related coverage

  • Debian 13.6 Released: Crucial Security and UEFI Fixes
  • Parrot OS 7.3 Released with Enhanced Performance and Optimized Architecture
  • EFS File System Removed from Linux Kernel in 7.3
  • Linux Kernel Surpasses 43 Million Lines
  • FreeBSD 15.1-RELEASE Launches with Network and Kernel Upgrades

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: kali linuxroot account

Follow:

  • Next story How to do website backup using lftp
  • Previous story How to scheduled backups between Linux hosts using scp

  • Recent Posts
  • Popular Posts
  • Tags
  • KindaRails2Shell Rails RCE vulnerability CVE-2026-66066 diagram

    Vulnerability

    KindaRails2Shell: Ruby on Rails CVE-2026-66066 RCE Flaw

    August 4, 2026

  • Global map illustrating the SNOWLIGHT malware cyberespionage campaign targets

    Malware

    SNOWLIGHT Malware Campaign Exposed by Open Directories

    August 4, 2026

  • Payroll Pirate AiTM phishing diagram showing session hijacking and payroll redirect attack flow bank phishing reimbursement Nova ransomware apology StablR stablecoin depeg hack

    Cyber Security

    OctLurk and SilkLurk Backdoors Target Central Asia

    August 4, 2026

  • SakDriver Windows kernel rootkit using DKOM and registry C2 channel to hide processes and evade EDR detection at Ring 0

    Malware

    SakDriver Rootkit: Windows Kernel Malware That Blinds EDR and Hides in the Registry

    August 4, 2026

  • Student hacks IIT websites to prove cybersecurity skills after admission rejection

    Cybercriminals

    Student Hacks IIT Websites After Cyber Security Rejection

    August 3, 2026

  • VMware vCenter vulnerability CVE-2026-59309 and CVE-2026-59310 rated CVSS 9.8 authentication bypass

    Vulnerability Report

    VMware vCenter CVE-2026-59309 and CVE-2026-59310 Rated CVSS 9.8

    July 29, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source Penetration Testing phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro