> On a similar theme - my standard recommendation: leave the shell on the
> true root account alone. Instead change the shell on the "toor" account,
> and set a toor password. Alternatively, create another similar account
> (one with uid and gid of zero) and meddle with that.

I delete the toor account almost straight away usually, and just set
root's shell to a Real Shell (/bin/sh).  I can do without two "root"
accounts, and I've never had a problem doing it this way.

