With Kerberos a hacked client where user 1 has authenticated can't impersonate user 2 unless that user has also authenticated on the client.
With sec=sys the client is simply trusted without any per-user authentication.
With Kerberos a hacked client where user 1 has authenticated can't impersonate user 2 unless that user has also authenticated on the client.
With sec=sys the client is simply trusted without any per-user authentication.