> so an attacker merely needs to take over a non-root user account (and their .bashrc) to get root
So if I don't use sudo then the problem with root is solved?