I have to really, really, really, strongly disagree with this in heavily 
emphasized bold type.

With a monitor running on every important machine, one of the things I 
like is that only the hobbit user can run hobbit, and the hobbit user 
can't do anything else - including sudo.  It's important not to let 
'little holes' like this pile up.  The pile gets large rapidly.

I could go on at length about specifics but i'll leave that to your 
local security list.  No one except no one should be in sudoers except 
those that consistently need root privs and use them responsibly.  
Preferably trusted humans!

