Package: suricata Version: 3.1.1-4 It might be a security improvement to let suricata run with non-root privileges and a special permission for the provided capture modes. Running as root might be a problem if a protocol parser or some other input-dependant code is exploitable.
Robert Haist ---------------- 2BC8 3F55 A400 7468 864C 680E 1B7C C8D4 D4E9 14AA