"toor" is no more and no less of a risk that "root".  Secure it as 
you would root.  Oh, and given sufficient opportunity, I can crack 
ANY password that uses characters from the ASCII set.  It's just not 
that difficult.  If you are going to expose this system the internet, 
I STRONGLY recommend that you use two-factor authentication and DO 
NOT RELY on passwords alone.

>>Can anyone tell me what function does the user "toor" that is put 
>>in by default by FBSD install  do?
>It's a backup root user.
>>im told its a security risk ...but unsure what it does ??
>I'm told a lot of things too, but that doesn't mean I believe all of 
>them :-)  If you're excessively paranoid, you can remove the user, 
>but if someone can get into your machine and crack root/toor's 
>password, you've got bigger issues to worry about.
