<<
<< He said he's using ssh, and since su and sudo both require you type a password if someone's sniffing his ssh session he's screwed anyway. >>
Yes, but sudo requires that you enter your user's password, not the root password. If someone's sniffing (not sure sniffing a ssh session would yeild much useful information anyway as ssh encrypts data) all they get is a user password, which they would have gotten from your login anyway. >>
Yes, he would be screwed anyways. But I still believe they are better ways to go about things in general, and you can lock down sudo pretty well. As far as sniffing ssh sessions, its possible, just really hard 😉