Live data from Hacker News

When was the famous "sudo warning" introduced? (2019)

retrocomputing.stackexchange.com

161–170 of 180 posts

Re: When was the famous "sudo warning" introduced? (2019)

#161

Earlier quoted context omitted.

Europe has its own version of this nonsense (GDPR cookie banners), but that stems from a different misguided belief. Europe believes that banners can affect markets. The US believes that banners can affect the law. Both are wrong.

>Both are wrong. What are 'GDPR cookie banners' [possessive, as in GDPR mandates them? And, what is the 'a different misguided belief...that can affect markets'?

GDPR demands consent, which naturally means a blocking modal that needs to be answered before any interaction is possible.

The misguided belief is that this is going to stop people from clicking on "accept".

Re: When was the famous "sudo warning" introduced? (2019)

#162

Earlier quoted context omitted.

That sounds like scientific coding, not serious coding

Serious coding like writing TODO apps for the latest WebTV?

Business applications are far more serious than any scientific code could ever hope to be

Re: When was the famous "sudo warning" introduced? (2019)

#163

I've got no "sudo" command on my main Linux workstation: the only way to log in as root is by using a Yubikey, from another computer, which is on a private LAN only shared between my workstation and my "terminal" (an old laptop which I know only use as some kind of remote console/terminal to log in as root on my workstation). So on my workstation I allow ssh root login, but only using keys (no password) (and only on…

A long time ago I also wasn't a fan of sudo so I used SSH only (password authentication from localhost). Eventually I stopped caring and stopped having strong opinions about sudo anymore.

Re: When was the famous "sudo warning" introduced? (2019)

#164

Earlier quoted context omitted.

> in all 150 countries this person's claimed to have visited. They had mountains of boring photos of traffic signs and fire hydrants and bollards and normal people on the street and in other public spaces living their lives and that kind of stuff in lots of countries, so I'm fairly sure they had been to them. :-) I don't think their take was a result of blindness to languages they don't/didn't know—we really do seem…

They had mountains of boring photos of traffic signs and fire hydrants and bollards and normal people on the street and in other public spaces living their lives and that kind of stuff in lots of countries, so I'm fairly sure they had been to them. :-) While I'm not familiar with the particular blogger of which you speak, I'm always skeptical about travel bloggers who claim to have been in an incredible number of pla…

With so much of the focus on differences between fire hydrants and street signs in different countries, the direct appeal was niche and the side-appeal that his very light and only occasional commentary on the photos was sometimes interesting, so that seems too indirect to possibly work as a way to catch a money-making amount of readership. This was tail-end-of-the-early-Web sort of stuff, started a few years before the rise of the contracted out ("Four-hour workweek" sorts trying to jumpstart that kind of "hustle", at least in the early days) monetized fake blog.

There was no pitch, and no ads, no self-promotion and barely any personal background at all, it was just "here's a crappy plain list of places I've been that breaks in surprising ways if JS is disabled" and if you clicked the links you'd get some broken-English (sometimes... other times you'll have to get out Google Translate) light commentary on photos he took there, though often there'd be several photos in a row with no commentary aside from maybe basic labels like "a bollard in [city]", that break down as about:

- 30% fire hydrants,

- 20% street signs or other road markers or traffic control devices,

- 20% bollards,

- 5% adaptive architectural details in very-cold or otherwise out of the ordinary environments

- 5% photos of the above things but specifically highlighting how much worse leftover French colonial infrastructure tends to be than British,

- 3% dudes shitting on beaches

- 2% disgusting illegal open air dumps, often on Pacific island "paradises" since I guess they're just covered in such things almost anywhere that's not a tourist hot-spot, which made a ton of sense in hindsight once pointed out—very limited space, lots of goods coming in, not rich enough to send the trash somewhere else, so of course that's a problem,

- nearly 0% any photos of normal landmarks or attractions you'd expect a tourist to take,

and 15% all else, usually observations of drug-related cafe culture stuff (I had no idea there were so many locally-tolerated-and-widely-openly-used but barely-known-to-Americans drugs out there before browsing that blog, often some kind of chewable leafy product or another), non-fancy food, whatever rusty barely-working ancient rural motorized mass transportation he'd ended up on this time, or slice-of-life observational things like a little "movie theater" in a very poor city that's some folding chairs in a little room with a smallish CRT TV and a DVD player at the front and a guy taking money at the doorless entry doorway (or dudes shitting on beaches, already covered separately because it featured weirdly often). Quite a bit of coverage of how shitty planned cities almost always are, and why (too much focus on big, wide roads that don't really need to be that big or wide, with huge unusable green spaces making them even worse, all in the name of getting big impressive sight lines on a few scattered monuments and buildings—this ties into the "place vs. non-place" concept I've seen used to criticize similar types of vision-first and "green space" obsessed city planning on other parts of the Web)

Like, the extreme focus on details most people wouldn't think to take a photo of and that are also kinda boring to nearly everyone convinced me the dude's angle was just that he... found comparing minor but common features of fundamental infrastructure more interesting than most people. When he had photos of anything but that sort of thing, it was more of an afterthought or accident, it seemed like. Plus there weren't even any ads or attempts to promote himself or products.

Re: When was the famous "sudo warning" introduced? (2019)

#165
post #92
post #16

Back in the 90s we were told ostentatiously to include "unauthorised access is not permitted" to the login prompt. Why? Because the login prompt said "please login:" and this was being read by some bush lawyer as an invitation to connect, and therefore would impede a case if we had a hacker login with a stolen password. I think it was founded on urban myth, but I assure you this is what we were told to do: add text t…

This is like the warning in emails about "not reading it if you aren't supposed to have received it" like yeah sure how do you know it's not for you then.

I love those 12-line long warnings when someone posts to an open email list.

Re: When was the famous "sudo warning" introduced? (2019)

#166

Earlier quoted context omitted.

All US parking garages have exactly that and it's so weird. Nobody reads them (what, from your car before paying and entering? LOL, nobody even reads the smaller notices attached to the payment machines , nor half the text the displays print during an interaction) so all the work at writing, printing, and posting them is just a kind of weird secular-religion ritual.

Now imagine it's everywhere. Entering a mall? You bet it's long. Entering a post office, bank, government agency? Of course. Entering a barber, restaurant, bar? Yep, even there. Entering a residential building? Yes, the inhabitants actually have a contract about their co-living and how they and others should behave in the common areas. This translates to ecommerce too - check out the terms of service and privacy poli…

I haven’t seen this in my country (I live in the country of Europe).

Re: When was the famous "sudo warning" introduced? (2019)

#167
post #33

Earlier quoted context omitted.

Remote identity only works well when paired with cloud storage; otherwise, you have a recipe for confusion. It works for game consoles because the scope of what needs to be stored in the cloud per-user is reasonably limited. It is problematic for PCs because the remote identity service is free but the free tiers of OneDrive, iCloud, etc. are too limited to actually hold all of the user's data, and it's hard to clearl…

No, I still prefer remote identity even ignoring "cloud" storage. It is nice having my desktop session just be able to negotiate the permissions with my NAS seamlessly without needing to have a separate user account for the NAS. Same with accessing file shares on any of my devices. On top of that it's also nice having that same identity work across all of my computers. When I change my password on one computer it is…

The kind of remote identity you're describing is what you can get with something relatively simple like LDAP. Unfortunately, that's not at all like what consumer operating systems are trying to support. Using a Microsoft account or iCloud account doesn't get you the easy NAS access, but does come with lots of other baggage.

Re: When was the famous "sudo warning" introduced? (2019)

#168

Earlier quoted context omitted.

No, I still prefer remote identity even ignoring "cloud" storage. It is nice having my desktop session just be able to negotiate the permissions with my NAS seamlessly without needing to have a separate user account for the NAS. Same with accessing file shares on any of my devices. On top of that it's also nice having that same identity work across all of my computers. When I change my password on one computer it is…

The kind of remote identity you're describing is what you can get with something relatively simple like LDAP. Unfortunately, that's not at all like what consumer operating systems are trying to support. Using a Microsoft account or iCloud account doesn't get you the easy NAS access, but does come with lots of other baggage.

"Relatively" simple. Save for getting access at different locations where there's no VPN connectivity between. I don't think it's usually recommended to have your LDAP endpoint public. And running an LDAP host is probably beyond most users, but basic home users can easily make a Microsoft or iCloud account.

And yes, using my Microsoft Account gets me pretty easy access to my NAS. I just grant permissions to MicrosoftAccount\me@hotmail.com and I get permissions. I just set it to MicrosoftAccount\my_wife@outlook.com and it works. I just grant it to MicrosoftAccount\my_friend@gmail.com (Microsoft accounts can be tied to any email) and it works.

I don't really experience much baggage though. Running an LDAP server to do it all comes with far more baggage and management woes for a home deployment. Trust me, I did it for many years before Windows 8+ was widespread. Domain trusts to log into friend's and family's computers with my account was pretty complex to manage and maintain along with actually bothering with site to site VPN connectivity. And when that one friend manages to wipe his forest root without backups...oof.

Re: When was the famous "sudo warning" introduced? (2019)

#169

Earlier quoted context omitted.

Actually, I have been wondering if using a Linux system as multi-user could be a boon in security. As single user, each and every process has full and complete control of $HOME. Instead, I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. Without going full QubeOS, get some amount of application separation so my photo utility do…

You can get halfway there with Flatpak and Distrobox. Or you could take a look at some of the "immutable" distros, such as openSUSE Aeon [1]. [1] https://aeondesktop.github.io/

Those solutions seem more aimed at keeping the system clean vs isolating what resources a program can access.

Flatpak does indeed get me part of the way there with better isolation, but available apps seem so scatter shot that I need a fallback mechanism for when there is not an official Flatpak artifact. Distrobox makes a point of indicating they are not a security boundary.

Re: When was the famous "sudo warning" introduced? (2019)

#170

Earlier quoted context omitted.

Actually, I have been wondering if using a Linux system as multi-user could be a boon in security. As single user, each and every process has full and complete control of $HOME. Instead, I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. Without going full QubeOS, get some amount of application separation so my photo utility do…

> Instead, I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. You’ll be interested to learn about systemd-nspawn. You can sandbox stuff with it really easily. It is like chroot so not really resource intensive, lighter than a container. I think a pretty useful thing you can do is boot ephemeral instances. So whatever someone do…

The nspawn does look interesting, and potentially exactly what I want. Although, this wiki page is dense enough that I am concerned I am going to somehow misconfigure it and be less secure than I would be without using it.

I Flatpak wherever I can, but several of my required applications are not first-party packaged, which makes me extra squeamish about installing them.

Post reply on HN