Earlier quoted context omitted.
I used to read an Eastern European world traveler photoblogger who’d been to damn near every country (even a lot that most folks from even semi-developed countries would consider far too dangerous or boring to be worth going out of your way to visit—he’d surely been to at least 150 countries, several more than once) and according to him the specific behavior of posting regulations and signs all over the place is prac…
The European way is to post a gigantic wall of text like 1.5 by 1.5 meters with small letters and a full binding contract somewhere close to the entrance.
When was the famous "sudo warning" introduced? (2019)
131–140 of 180 posts
Re: When was the famous "sudo warning" introduced? (2019)
#132Earlier quoted context omitted.
We had a client insist that the SSH prompt be changed to include a half-page rambling about it being an "proprietary system" and "access prohibited for non-authorized users", something like that. Failing to include their specific wording, when we did their new staging setup, was a critical, must fix now bug. Their argumentation was that it was a regulatory requirement and would allow for prosecution.
This is a regular sight when accessing a US government computer system. Even managing things like Global Entry come with such a warning.
Re: When was the famous "sudo warning" introduced? (2019)
#133Earlier quoted context omitted.
Perhaps it is useful for countries that still don't have any real computer crime laws? Because in most western nations it would be totally pointless.
No, the US is the main country that loves these messages. Have you seen the size of universities or the government ? It's just clerical staff doing make believe work. Go to any .gov website. They'll throw up a wall of bs before you log in (e.g., https://ttp.dhs.gov/ ).
This is unlike trespassing in the US, however, which does require informing the person (written in a conspicuous location, or direct verbal conversation) they are unwelcome on whatever land they began accessing, and allowing them to promptly retreat, before any violation is committed. Access is generally permitted (e.g., to allow for unsolicited deliveries) prior to such communication.
Re: When was the famous "sudo warning" introduced? (2019)
#134Earlier quoted context omitted.
The European way is to post a gigantic wall of text like 1.5 by 1.5 meters with small letters and a full binding contract somewhere close to the entrance.
All US parking garages have exactly that and it's so weird. Nobody reads them (what, from your car before paying and entering? LOL, nobody even reads the smaller notices attached to the payment machines , nor half the text the displays print during an interaction) so all the work at writing, printing, and posting them is just a kind of weird secular-religion ritual.
This translates to ecommerce too - check out the terms of service and privacy policies of some European web shops.
Re: When was the famous "sudo warning" introduced? (2019)
#135Re: When was the famous "sudo warning" introduced? (2019)
#136Earlier quoted context omitted.
For anyone else who hasn't heard it before, a bush lawyer is "One who is not qualified in law yet attempts to expound on legal matters." https://en.m.wiktionary.org/wiki/bush_lawyer
Perhaps "bush lawyer" was the inspiration for "hedge wizard." https://www.reddit.com/r/DnD/comments/zetwkt/what_exactly_is...
Re: When was the famous "sudo warning" introduced? (2019)
#137Earlier quoted context omitted.
These days if the device is expected to be ~always internet-connected (increasingly a safe bet) it probably makes more sense for both the developers and users to handle multiple users with a remote identity provider (email, individual account for the particular service, etc.) rather than implementing identity per-device. I'm pretty sure gaming consoles have had support for this for a long time (at least since xbox 36…
Remote identity only works well when paired with cloud storage; otherwise, you have a recipe for confusion. It works for game consoles because the scope of what needs to be stored in the cloud per-user is reasonably limited. It is problematic for PCs because the remote identity service is free but the free tiers of OneDrive, iCloud, etc. are too limited to actually hold all of the user's data, and it's hard to clearl…
It is nice having my desktop session just be able to negotiate the permissions with my NAS seamlessly without needing to have a separate user account for the NAS. Same with accessing file shares on any of my devices.
On top of that it's also nice having that same identity work across all of my computers. When I change my password on one computer it is changed on all the computers I use. I never have to think "what was the password for this computer again?" The same account on my gaming PC is the same account on my personal laptop, my main home server, my wife's tablet when I use that, other gaming PC's at friend's houses, etc.
Personally, I really prefer using an IdP in my personal life, especially when its pretty stupid simple to set up and use. It can make a lot of things easier.
Re: When was the famous "sudo warning" introduced? (2019)
#138Earlier quoted context omitted.
The system does know who I am: the command is coming from me. An attacker doesn't need to elevate privileges to compromise me: he can steal whatever he needs without becoming root. He can replace sudo and steal my password too. The whole concept of my personal user account needing to elevate to root to make "system" changes is a relict of long-gone days of BBSes, shell accounts, and time sharing. These days, we shoul…
Your first paragraph is obviously wrong, so maybe dial back the pronouncements. What you are advocating for was a disaster for Windows, btw.
No. Maybe have an argument instead of pointing and shrieking?
> What you are advocating for was a disaster for Windows, btw.
No it wasn't. I think UAC is a waste of time, but the type-your-password-into-sudo camp is advocating something strictly worse than UAC.
I don't need to type my god damned password to install a program on iOS or Android.
Re: When was the famous "sudo warning" introduced? (2019)
#139Earlier quoted context omitted.
All US parking garages have exactly that and it's so weird. Nobody reads them (what, from your car before paying and entering? LOL, nobody even reads the smaller notices attached to the payment machines , nor half the text the displays print during an interaction) so all the work at writing, printing, and posting them is just a kind of weird secular-religion ritual.
Now imagine it's everywhere. Entering a mall? You bet it's long. Entering a post office, bank, government agency? Of course. Entering a barber, restaurant, bar? Yep, even there. Entering a residential building? Yes, the inhabitants actually have a contract about their co-living and how they and others should behave in the common areas. This translates to ecommerce too - check out the terms of service and privacy poli…
It's possible EU states have gotten worse ("worse"—I mean, it's basically harmless, which is why it just fades into the background and it's easy to not even notice it, aside from that the whole thing's a little bit of wasted work) about this since his writing and since I've been there, as the latest of his posts I read were probably from travel in the late '00s, and I haven't been to any part of Europe myself since not long after that.
Re: When was the famous "sudo warning" introduced? (2019)
#140Earlier quoted context omitted.
My networking instructor still suggests this today when configuring the login for routers and switches
It's as useful as people that say they are not lawyers when commenting online.