# Install NodeRED under separate user on RaspberryPi?

**URL:** <https://discourse.nodered.org/t/install-nodered-under-separate-user-on-raspberrypi/19728>\
**Category:** General\
**Created:** [30 December 2019 07:58 UTC](https://discourse.nodered.org/t/install-nodered-under-separate-user-on-raspberrypi/19728 "2019-12-30T07:58:50Z")\
**Posts on this page:** 3\
**Page:** 2

<div class="post-metadata">

**Author:** ![gunter](https://avatars.discourse-cdn.com/v4/letter/g/e480ec/32.png) [@gunter](https://discourse.nodered.org/u/gunter)\
**Post date:** [2 January 2020 20:43 UTC](https://discourse.nodered.org/t/install-nodered-under-separate-user-on-raspberrypi/19728/21 "2020-01-02T20:43:54Z")

</div>

Via renaming of the original account I created my personal account. But exactly because of the thinking of @TotallyInformation I now created a separate user, which just runs Node-RED. I became kind of fluent with Linux, so I now also like some nerdy stuff there 😉 And this new user needed to support this as well.

And the original anxiety, which sparked my whole topic is exactly, what you described here: [Happy New Year (well maybe for some) ... A security warning](https://discourse.nodered.org/t/happy-new-year-well-maybe-for-some-a-security-warning/19793) Of course I will also take additional measures, when ever making Node-RED accessible from the internet. But I like multiple safety nets, especially for such a mighty thing as Node-RED, which I have not yet understood and therefore cannot assess the risk and potential mitigation strategies.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [2 January 2020 22:04 UTC](https://discourse.nodered.org/t/install-nodered-under-separate-user-on-raspberrypi/19728/22 "2020-01-02T22:04:10Z")

</div>

Well, I'm glad that post helped & glad that you've learned some new things along the way - the best way to stay young I find! 😀

> [@gunter](#):
>
> I like multiple safety nets

Me too. It's hard to be _too_ paranoid. On the Internet, there's _always_ someone out to get you! 🤔

> [@gunter](#):
>
> which I have not yet understood and therefore cannot assess the risk and potential mitigation strategies

You've already done more than many and you shouldn't stress out too much. In reality, for most people, the risks really are quite small. Following sensible cyber security practices will certainly keep you pretty safe.

If you want to learn more, here are a couple of useful places to start:

> **[OWASP Foundation, the Open Source Foundation for Application Security | OWASP...](https://owasp.org/)**
>
> OWASP Foundation, the Open Source Foundation for Application Security on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.

> **[AppSecIL2016\_NodeJS-Security\_LiranTal.pdf](https://owasp.org/www-pdf-archive/AppSecIL2016_NodeJS-Security_LiranTal.pdf)**
>
> 2.93 MB

> **[Secure design principles](https://www.ncsc.gov.uk/collection/cyber-security-design-principles)**
>
> Guides for the design of cyber secure systems

> **[Security Best Practices for Express in Production](https://expressjs.com/en/advanced/best-practice-security.html)**

> **[Developing Secure Node.js Applications — A Broad Guide](https://blog.insiderattack.net/developing-secure-node-js-applications-a-broad-guide-286afdec69ce)**
>
> Security of Node.js applications has been very important since it is becoming a widely used platform for developing web applications/web…

> **[How to make your NodeJS dynamic application or API secure](https://itnext.io/make-security-on-your-nodejs-api-the-priority-50da8dc71d68)**
>
> If you are a back-end or a full-stack (web) developer, you probably heard terms such as: DOS Attacks, XSS, SQL/NoSQL Injection Attacks and…

---

<div class="post-metadata">

**Author:** ![gunter](https://avatars.discourse-cdn.com/v4/letter/g/e480ec/32.png) [@gunter](https://discourse.nodered.org/u/gunter)\
**Post date:** [4 January 2020 18:22 UTC](https://discourse.nodered.org/t/install-nodered-under-separate-user-on-raspberrypi/19728/23 "2020-01-04T18:22:54Z")

</div>

Thanks, this looks very interesting. If I had known in what rabbit hole I got myself with this project 🤔

[Previous page](https://discourse.nodered.org/t/install-nodered-under-separate-user-on-raspberrypi/19728.md?page=1)
