You should always assume that anybody with a shell access or physical access can become root and act accordingly.
Unfortunately, you're right 👍
reply