Live data from Hacker News

When was the famous "sudo warning" introduced? (2019)

retrocomputing.stackexchange.com

151–160 of 180 posts

Re: When was the famous "sudo warning" introduced? (2019)

#151
post #63

Earlier quoted context omitted.

> Instead, I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. You’ll be interested to learn about systemd-nspawn. You can sandbox stuff with it really easily. It is like chroot so not really resource intensive, lighter than a container. I think a pretty useful thing you can do is boot ephemeral instances. So whatever someone do…

I read a good chunk of that wiki link, but didn't really come away with an understanding of how it differs from just using Docker for sandboxing an app. Did you have any insight there you might share?

  > how it differs from just using Docker 
It uses the system.

You’re missing the trees for the forest. At a high level they are the same, just as with LXC or podman or others. But it’s the details which are really important. Because your leveraging the system you can really shrink down the size, another user mentioned. But there’s also a convenience in just being able to use systemd when its already built into your system.

I suggest also reading

  man systemd-nspawn

Just type it into your terminal, you don’t need to install anything

Re: When was the famous "sudo warning" introduced? (2019)

#152

Earlier quoted context omitted.

> It’s a funny artifact because most people today use, and have only used Linux in a “single user” context. The “local system administrator” is me! Except if you're on a team of sysadmins running a fleet of systems, either a whole bunch of cattle and/or numerous pets. There are numerous occasions that I have to SSH to look at something on an individual system, and it's best practice to go in as yourself and then sudo…

What is (theoretically, or practically) being achieved by running sudo instead of just logging in as root? Can you give an example that justifies typing your password up to hundreds of times per day coupled with deliberate hashing delays?

If a network intrusion detector warns about something being changed, you can review the logins to see that it happened right as an authorized person accessed the box. A common practice is to not allow root direct ssh access.

Re: When was the famous "sudo warning" introduced? (2019)

#153
post #105

Earlier quoted context omitted.

Other way round for me

What kind of sysadmins are they then? I don't want to sound dismissive, but is a "windows sysadmins" a thing? Do companies run windows on servers?

> Do companies run windows on servers?

All of the Fortune 500 probably does.

Re: When was the famous "sudo warning" introduced? (2019)

#154
post #3

It’s a funny artifact because most people today use, and have only used Linux in a “single user” context. The “local system administrator” is me!

And that's why we should 1) switch from using "sudo some-command --some-argument" to "some-command --some-argument" in which some-command authenticates and elevates via polkit, and 2) configure polkit to allow the initial human user of the machine to elevate without typing a password. #2 is just a default, and special configurations can of course override it and return a configuration much like what we have today. Bu…

>if I'm installing Ubuntu on my laptop and I, as my regular user, want to install audacity, I shouldn't have to re-enter my password!

I may be overgeneralizing, or I may not. I feel like people who hate retyping their passwords (it's most of people) are impatient people apt to take other shortcuts when they can, and therefore can't either be trusted with things like C pointers. Just don't take shortcuts, life's too short for shortcuts.

I retype all my passwords all the time, and I don't let my browsers remember them either. It really doesn't bother me, and a side benefit is, I never forget my passwords.

Re: When was the famous "sudo warning" introduced? (2019)

#155
post #93

Earlier quoted context omitted.

For anyone else who hasn't heard it before, a bush lawyer is "One who is not qualified in law yet attempts to expound on legal matters." https://en.m.wiktionary.org/wiki/bush_lawyer

TIL, this was my first time seeing the term. I just assumed that the poster had left out the second word of "bush league". That would mean something similar but subtly different, though (a lawyer not up to professional standards).

I've heard a similar formulation of "barracks lawyer" from military folks. The dude who gives terrible advice but can use enough legal jargon to make it sound convincing.

Re: When was the famous "sudo warning" introduced? (2019)

#156

Earlier quoted context omitted.

Sounds like you have never been to Europe. Here they make you actually sign (as in pen and paper) this stuff before they give you access.

Europe has its own version of this nonsense (GDPR cookie banners), but that stems from a different misguided belief. Europe believes that banners can affect markets. The US believes that banners can affect the law. Both are wrong.

>Both are wrong.

What are 'GDPR cookie banners' [possessive, as in GDPR mandates them? And, what is the 'a different misguided belief...that can affect markets'?

Re: When was the famous "sudo warning" introduced? (2019)

#157

Earlier quoted context omitted.

Now imagine it's everywhere. Entering a mall? You bet it's long. Entering a post office, bank, government agency? Of course. Entering a barber, restaurant, bar? Yep, even there. Entering a residential building? Yes, the inhabitants actually have a contract about their co-living and how they and others should behave in the common areas. This translates to ecommerce too - check out the terms of service and privacy poli…

The US does it, too, but it's often separate sheets of printed paper and a few standard-issue laminated posters. Plus a few briefer notices posted to the doors, especially at larger businesses. It's possible EU states have gotten worse ("worse"—I mean, it's basically harmless, which is why it just fades into the background and it's easy to not even notice it, aside from that the whole thing's a little bit of wasted w…

This has definitely been the case since early 90s all around Eastern Europe. I grew up there. Maybe he didn't notice - these walls of text are close to the entrance but definitely not the most highlighted feature there. I'd guess many locals don't even know - it's just that I like to read random stuff.

Re: When was the famous "sudo warning" introduced? (2019)

#158

Earlier quoted context omitted.

It's the sort of cultural blindness that comes with not being able to read the native languages in all 150 countries this person's claimed to have visited. Once you're able to read a new language, you see all kinds of new signs, especially when you visit a new country. It's like how people who only read English think of Japan as some kind of blissful artspace, when the reality is that it is far more overloaded with a…

> in all 150 countries this person's claimed to have visited. They had mountains of boring photos of traffic signs and fire hydrants and bollards and normal people on the street and in other public spaces living their lives and that kind of stuff in lots of countries, so I'm fairly sure they had been to them. :-) I don't think their take was a result of blindness to languages they don't/didn't know—we really do seem…

They had mountains of boring photos of traffic signs and fire hydrants and bollards and normal people on the street and in other public spaces living their lives and that kind of stuff in lots of countries, so I'm fairly sure they had been to them. :-)

While I'm not familiar with the particular blogger of which you speak, I'm always skeptical about travel bloggers who claim to have been in an incredible number of places.

I say this because it's very easy to hire someone on the other side of the planet to take a series of digital photos of their lives and tourist attractions for a week or so and then you, yourself, post a travel blog with their content. Because of exchange rates, often the more exotic the location, the cheaper it is. Sometimes incredibly cheap. Like $20 to some far-off rando can reap thousands in Google Ads for a web site.

I know because I used to do this for an American travel company way back in 2015-ish. Back then, I'd often hire cab drivers to do it because they always had a camera phone with them, and they were always going to airports and restaurants and tourist places and standing around with time to kill anyway.

Back then it would be weird to have a picture of yourself in a travel blog, but since everyone is a narcissist these days, you'd have to Photoshop or AI yourself into the photos and videos to be believable, but that's trivial now.

Again, I'm not saying your guy is a big faker. I'm just saying there are big fakers out there, so be careful who you believe.

Re: When was the famous "sudo warning" introduced? (2019)

#159

I've got no "sudo" command on my main Linux workstation: the only way to log in as root is by using a Yubikey, from another computer, which is on a private LAN only shared between my workstation and my "terminal" (an old laptop which I know only use as some kind of remote console/terminal to log in as root on my workstation). So on my workstation I allow ssh root login, but only using keys (no password) (and only on…

Any reason not to run SSH on localhost only? This way there would be no network requirement whatsoever.

I am not trying to criticize, but am just curious what you gain by having this access split across two machines?

Re: When was the famous "sudo warning" introduced? (2019)

#160
post #34

Earlier quoted context omitted.

I agree that multi-user should go away for modern server workloads, however, users are used as a blast door. Mainly because Linux's security model is lacking. systemd for example commonly runs services under separate users to make it more difficult for a compromised application to elevate privileges. Android does something similar AFAIK. Users should have never became a security boundary to isolate applications, but…

>systemd for example commonly runs services under separate users Doesn't this have to be manually setup. Can i make systemd to run a service under a temporary user automatically.

Yes?

https://www.freedesktop.org/software/systemd/man/latest/syst...

Post reply on HN