concerns stemmed from the various mentions of everything being in /root which just seems like plain bad security practice.
however a cursory review of the codebase indicates that most of the services run as the zulip user and authentication uses certificates rather than passwords.
however a cursory review of the codebase indicates that most of the services run as the zulip user and authentication uses certificates rather than passwords.