Live data from Hacker News

When was the famous "sudo warning" introduced? (2019)

retrocomputing.stackexchange.com

171–180 of 180 posts

Re: When was the famous "sudo warning" introduced? (2019)

#171

Earlier quoted context omitted.

Actually, I have been wondering if using a Linux system as multi-user could be a boon in security. As single user, each and every process has full and complete control of $HOME. Instead, I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. Without going full QubeOS, get some amount of application separation so my photo utility do…

> As single user, each and every process has full and complete control of $HOME. I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. This is what OpenBSD's unveil does. Firefox for example only has access to ~/Downloads (and some stuff in ~/.mozilla, ~/.config, ~/.cache) in my home directory.

Now this looks promising for mere mortals. I found jart's Linux port of pledge[0] which makes it seem possible to simply wrap utilities through a preceding script. If I couple this with distrobox/podman (which should work fine?) I might be able to pretty seamlessly lock down utilities by default with minimal shenanigans.

Assuming it does what it says on the tin, and it can work with GUI apps, this would get me almost all the way.

[0] https://justine.lol/pledge/

Re: When was the famous "sudo warning" introduced? (2019)

#172
post #72

Earlier quoted context omitted.

Actually, I have been wondering if using a Linux system as multi-user could be a boon in security. As single user, each and every process has full and complete control of $HOME. Instead, I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. Without going full QubeOS, get some amount of application separation so my photo utility do…

Yeah that's possible but its still security as an afterthought, bolted onto an existing system. And it's a bad UX also. As a user, I don't want to deal with fake users, for example.

*Nix was designed to be multi-user. It's probably the only security boundary that was present from nearly the start. I think there are some rough edges on the user-per-application model, but it should all be scriptable so that the machinations are mostly hidden.

Re: When was the famous "sudo warning" introduced? (2019)

#173

Earlier quoted context omitted.

The kind of remote identity you're describing is what you can get with something relatively simple like LDAP. Unfortunately, that's not at all like what consumer operating systems are trying to support. Using a Microsoft account or iCloud account doesn't get you the easy NAS access, but does come with lots of other baggage.

"Relatively" simple. Save for getting access at different locations where there's no VPN connectivity between. I don't think it's usually recommended to have your LDAP endpoint public. And running an LDAP host is probably beyond most users, but basic home users can easily make a Microsoft or iCloud account. And yes, using my Microsoft Account gets me pretty easy access to my NAS. I just grant permissions to Microsoft…

> And yes, using my Microsoft Account gets me pretty easy access to my NAS. I just grant permissions to MicrosoftAccount\me@hotmail.com and I get permissions. I just set it to MicrosoftAccount\my_wife@outlook.com and it works. I just grant it to MicrosoftAccount\my_friend@gmail.com (Microsoft accounts can be tied to any email) and it works.

What NAS, exactly? And how does it handle non-Windows clients?

What you're describing doesn't seem to be something that eg. run of the mill Samba offers, and it's something that Microsoft seems to be changing with every major version of Windows.

> Save for getting access at different locations where there's no VPN connectivity between.

Getting access to what?

Re: When was the famous "sudo warning" introduced? (2019)

#174

Earlier quoted context omitted.

"Relatively" simple. Save for getting access at different locations where there's no VPN connectivity between. I don't think it's usually recommended to have your LDAP endpoint public. And running an LDAP host is probably beyond most users, but basic home users can easily make a Microsoft or iCloud account. And yes, using my Microsoft Account gets me pretty easy access to my NAS. I just grant permissions to Microsoft…

> And yes, using my Microsoft Account gets me pretty easy access to my NAS. I just grant permissions to MicrosoftAccount\me@hotmail.com and I get permissions. I just set it to MicrosoftAccount\my_wife@outlook.com and it works. I just grant it to MicrosoftAccount\my_friend@gmail.com (Microsoft accounts can be tied to any email) and it works. What NAS, exactly? And how does it handle non-Windows clients? What you're de…

> What NAS, exactly?

A small low power x86 Windows box. Used to be an older gaming PC, swapped for a lower power CPU with integrated graphics. Runs storage for an array, VMs, containers, video transcoding, etc.

Non-Windows clients can also log in with local accounts or with that same MicrosoftAccount realm login username/password. I've used some Pi's and other Linux boxes mounted that way in the past.

But it seems like it's decently well supported in Samba to auth like this though. I'm not sure what happens when their Microsoft account password changes though.

https://forums.unraid.net/topic/117723-allow-at-sign-in-smb-...

> Getting access to what?

Getting access to the LDAP server to handle auth. If I hop on my friend's spare computer at his house, how is it going to reach out to my LDAP server at home?

Same thing when I'm hopping on my dad's computer, or if he wants to use mine when he's visiting. This way we can just use our own logins and have access to our own files, resources, settings, etc. Regardless of whatever computer we're using. If I want him to copy his recent trip photos to the archive when.he comes over he can drag and drop them into the network share on the NAS with his own credentials on his own computer, as I've granted his Microsoft account access to write to the family photos. He doesn't need to remember his password to my NAS, his desktop login is his auth. Same when I'm at a friend's house and on his computer. I just want to pull some big file off my laptop over the network, I can just open up my shares on my laptop and grab whatever. I don't need a separate login to manage.

There's so much stuff that's just so smooth and seamless using an external, managed, widely shared IdP to handle identity management. Some negatives and risks, no doubt. But to me, it's a worthwhile trade off given how easy it makes these kinds of workflows I encounter daily.

Re: When was the famous "sudo warning" introduced? (2019)

#175

Earlier quoted context omitted.

Love it! I've seen a lot of signs like, "prohibited items are not allowed in facility." Especially TSA signs at the airport which also include guns and knives and such in big red circles with lines through them. I always wonder if those signs were made by a brilliant low-grade troll or not. I once added text that said, "Unauthorized access is not authorized" as a low-grade troll, and people liked it so it stayed

No Spitting. The Mgt.

"The Midget."

Re: When was the famous "sudo warning" introduced? (2019)

#176

Earlier quoted context omitted.

Now imagine it's everywhere. Entering a mall? You bet it's long. Entering a post office, bank, government agency? Of course. Entering a barber, restaurant, bar? Yep, even there. Entering a residential building? Yes, the inhabitants actually have a contract about their co-living and how they and others should behave in the common areas. This translates to ecommerce too - check out the terms of service and privacy poli…

I haven’t seen this in my country (I live in the country of Europe).

I believe you didn't see it, many locals didn't. But I bet you can find it if you go looking. I personally check this stuff, it's my kind of weirdness, and I assure you it's the case in every EU country (I checked) and I'd bet it's the case in every European country.

Re: When was the famous "sudo warning" introduced? (2019)

#177

Earlier quoted context omitted.

Your first paragraph is obviously wrong, so maybe dial back the pronouncements. What you are advocating for was a disaster for Windows, btw.

> dial back the pronouncements. No. Maybe have an argument instead of pointing and shrieking? > What you are advocating for was a disaster for Windows, btw. No it wasn't. I think UAC is a waste of time, but the type-your-password-into-sudo camp is advocating something strictly worse than UAC. I don't need to type my god damned password to install a program on iOS or Android.

Moving validation to an app store is doable but it’s very costly and not a complete solution. Sandboxing is here. Multiple layers is generally better, and you can configure your system as you see fit.

Re: When was the famous "sudo warning" introduced? (2019)

#178

Earlier quoted context omitted.

> Instead, I would prefer all applications were sandboxed to their own little respective areas with minimal access to data unless explicitly authorized. You’ll be interested to learn about systemd-nspawn. You can sandbox stuff with it really easily. It is like chroot so not really resource intensive, lighter than a container. I think a pretty useful thing you can do is boot ephemeral instances. So whatever someone do…

The nspawn does look interesting, and potentially exactly what I want. Although, this wiki page is dense enough that I am concerned I am going to somehow misconfigure it and be less secure than I would be without using it. I Flatpak wherever I can, but several of my required applications are not first-party packaged, which makes me extra squeamish about installing them.

For security read on systemd-exec https://www.freedesktop.org/software/systemd/man/latest/syst...

Re: When was the famous "sudo warning" introduced? (2019)

#179
post #34

Earlier quoted context omitted.

I agree that multi-user should go away for modern server workloads, however, users are used as a blast door. Mainly because Linux's security model is lacking. systemd for example commonly runs services under separate users to make it more difficult for a compromised application to elevate privileges. Android does something similar AFAIK. Users should have never became a security boundary to isolate applications, but…

> Linux's security model is lacking It's not lacking at all. The root + users model is common not only across OSes but also all sort of physical devices.

Nah, its been lacking since inception, with people trying things like chroot jails and suid bits decades before Linux was a twinkle in an eye, and we still regularly fail at running untrusted code.

Re: When was the famous "sudo warning" introduced? (2019)

#180
post #107
post #59

Earlier quoted context omitted.

Interesting! I use Guix, I wonder if the fundamental idea can be translated here too. Do you have any links for the Nix-related stuff?

Arrg, I just realized I lost my demo system in a recent drive failure. So I don't have anything I can show directly... but this is my recollection. I used systemd-nspawn containers https://nixos.wiki/wiki/NixOS_Containers . For each container I'd run a `filterway` process with a unique app id outside the container and mount the filterway wayland socket inside the container, then wayland programs in the container woul…

Impressive! I'm not sure Guix has something similar to nspawn containers

Hyprland has a way to put unique borders per appid too, I think.

Post reply on HN