5 ms·
Perhaps a better question to ask would be "why is any process allowed to do this by default in 2021?"
by dmart 5y ago
Perhaps a better question to ask would be "why is any process allowed to do this by default in 2021?"
- acatton 5y agoBecause it's a legitimate behaviour. htop needs to do this, it's literally its main feature. You can use hidepid=2 to prevent users from seeing other user's processes list.[1] But I don't want my OS to ask me "do you want to allow htop to access the list of your processes" — à la Windows Vista — every time I want to run htop to see my user processes. The issue here is closed source software with no way to inspect what they do. If one really want to run closed source programs which were not vetted by their distro's maintainers, they should use firejail.[2] [1] https://www.cyberciti.biz/faq/linux-hide-processes-from-other-users/ https://www.cyberciti.biz/faq/linux-hide-processes-from-othe... [2] https://firejail.wordpress.com/ https://firejail.wordpress.com/
- mixmastamyk 5y agoWhitelisting htop would be a simple matter.
- gwbas1c 5y agoI think the nags discourage sketchy behavior. It makes some of the lackluster product managers think twice about unreasonable program behavior.
- OJFord 5y ago> But I don't want my OS to ask me "do you want to allow htop to access the list of your processes" — à la Windows Vista — every time I want to run htop to see my user processes. Why would it be every time? Say yes once to htop, no to Zoom. Sort of like Android/iOS permissions. Or just require root. No way I'd give it to Zoom, htop maybe.
- acatton 5y agoThe issue is that the model on Linux is different. As opposed to walled gardens, the assumption is that applications are cooperative, therefore there is no need for such "authorization systems". The security model on Linux is based on blacklist, with solutions like firejail. Also, what's the points of these nags? Most people will just say "OK" anyway because they want to access the features they were promised.
- forgotpwd16 5y agoThe issue is that this model heralds from the 60s when such problems weren't even considered.
- acatton 5y agoThat is a way to see it. I see it differently, for me the main issue is the fact that people run random software that were not even vetted. If you dnf/apt install everything from the official repos of your distro, you wont have any misbehaving apps. And that model still holds. And as I explained, other security models don't work either. People will just whitelist the app, or click "Accept" anyway, because they want the feature now! What's the point of nagging with a modal window "your random app, that you installed from a random website on the internet, which means you really want to use this specific app, is behaving in a shady manner, are you okay with this?"
- bamboozled 5y agoIf you dnf/apt install everything from the official repos of your distro, you wont have any misbehaving apps. And that model still holds. How do you know this? I hear this a lot, I've built packages myself, only because I needed them in a hurry. I never really went through the source code to make sure it's safe. Maybe others did, but I didn't, people installed the package, maybe they were hacked, who knows? Just saying...
- acatton 5y agoWhen a package lands in Debian Sid or in Fedora Rawhide, there is a group/subculture of nerds who like to inspect it and report any misbehaviour. [1] [2] I usually do this directly on the source project, but some people in this subculture do it in their distro. Also I'm surprised your packages landed in Debian/Fedora, because there is a review process… I'm not talking about a ppa repo or a copr repo, anybody can run that. I'm talking about packages in the official repositories. Installing software from a random ppa or copr repo is the same as curl | sudo sh, nobody vetted this. [1] Type of bugs they report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=792580 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=792580 [2] https://www.fsf.org/blogs/community/who-actually-reads-the-code https://www.fsf.org/blogs/community/who-actually-reads-the-c...
- swiley 5y agoBecause you're not supposed to be downloading random binaries from the internet and running them like some toddler on Windows or OSX would. STOP DOING THAT.
- fsflover 5y agoThis is not the case on Qubes OS, which I use. If you care about security, can't recommend it enough.