10 ms·
> pkexec is installed by default on all major Linux distributions (we exploited Ubuntu, Debian, Fedora, CentOS, and other distributions are probably also ex
by kator 5y ago
> pkexec is installed by default on all major Linux distributions (we
exploited Ubuntu, Debian, Fedora, CentOS, and other distributions are
probably also exploitable);
I don't find it on any of the servers I manage, it appears to be installed with graphical desktop only?
- throwaway984393 5y agoPolicykit's sole purpose is to provide an abstraction to let modern X server applications press a suspend or power off button. It's the same kind of garbage as DBus. The modern Linux desktop is absurd.
- skeptical1 5y agoYes, this is exactly why I don't run any of this crap on my distro. No dbus, no polkit, no systemd, nothing. Computer security is already enough of a nightmare without all this crap added on and linked in to everything.
- 400thecat 5y agoI also have my system without polkit and without systemd. But how do you get rid of dbus? It seems to be needed for many GUI applications
- skeptical1 5y agoSome programs can be configured to run without it. Others require patching to remove it. Some patches are trivial, others not so much. I've done a lot of patching, with still more required to get other applications running that I want to use. At some point I'm planning to build a "dummy" dbus library that can be linked against but actually does nothing at all, but I haven't gotten around to it yet.
- crazy_hombre 5y agoOh no, an application has bugs. Must get rid of it!
- skeptical1 5y agoHas bugs, is way too complex for the given functionality, and is completely unneeded in the first place--yes, get rid of the damn thing. Unless of course you enjoy getting "your" system OWNED and dominated by bad actors. My custom distro beats the brakes off junkware like Ubuntu and (lol) Windows in startup time and responsiveness, and has all of the functionality I need, with half the code and as a result much fewer gaping security holes. Computer security is an absolute nightmare these days. Intelligent people should be simplifying things and stripping everything down to the bare minimum, instead of stacking more crud on top of endless crud. Those who fail to SECURE their systems and workflows will one day in the near future be surprised as shit to find that the entire "cloud" has been hacked and destroyed by worms and their system trashed right along with it. At that time, the world will be divided into two camps: computer owners (me and my kind) and non computer owners (everyone else.)
- palmetieri2000 5y agoRegardless of how genius your distro is this reeks of self importance and arrogance to an almost satirical level.
- skeptical1 5y agoWho cares? If you don't take computer security seriously, you won't be computing much longer. Before it's over with, mine will be the only opinion still in existence. It's called "natural selection."
- chaxor 5y agoYou don't have Firefox or any browser? How are you posting? W3m? I would imagine that these have an enormous amount of bugs and security issues if parts of basic Linux programs are riddled enough with them by your standards.
- emptybottle 5y agoMe too, the only process I run is init. I don’t even mount a root filesystem. Can’t root without a root is what I always say! /s
- foxfluff 5y agoWhy does pipewire depend on it? Otherwise I'd just remove it right now.
- throwaway984393 5y agoSigh... Because systemd, dbus, polkit, pulseaudio, rtkit, etc are invasive weeds. Apps now depend on them exclusively so often that you have to provide some shim to replace their ABI if you don't want to use those components. I can't remember the specifics but pipewire probably only casually references it as part of a compatibility layer. In Alpine I'm pretty sure you can run pipewire without polkit but I'd have to check.
- throwawaysysd 5y agoOr it could be because those libraries actually do something and users want them? I really don't get these complaints. Is the C library an "invasive weed" because C programs require an ABI compatible C library to run?
- foxfluff 5y agoThey are invasive if they somehow end up on your system even if you don't need them and didn't ask for it. The C library is something that I actually need, unlike a GUI sudo prompt for.. audio? I don't even know what such a prompt looks like because I've never seen one.
- throwawaysysd 5y agoI'm sorry, now I really don't understand. If these libraries shipped with your distro, you asked for them. If they were dependencies of a package you installed, you asked for them. It's bizarre to me that there are hundreds of Linux distros with every combination of packages you could possibly ask for and I still see this complaints. It's very likely you didn't see a prompt because your distro configured it to not require a password. If you want to configure it to require a password, the system lets you do that. This is just another choice you have.
- ismaildonmez 5y agoConfidently incorrect.
- deleted 5y ago[deleted]
- tomputer 5y agoCan confirm. I just checked Debian 7/8/9/10/11 servers and none has pkexec (or policykit-1) installed.
- blibble 5y agoseems libvirt-daemon pulls it in too
- pavon 5y agoYes. On my Debian Stable desktop the only packages that required it were: * rtkit - optional dependency of PulseAudio to grant its processes realtime priority. * colord - optional color profile dbus service. * gparted - hard dependency to give it permission to reformat disks. I like to keep a minimal system, so I went ahead and removed them all. Will see if audio performance suffers.
- throwawaysysd 5y agoYou can still get realtime priority for threads without rtkit but you will have to set the appropriate permissions on your user. See the section on privileges: https://www.man7.org/linux/man-pages/man7/sched.7.html https://www.man7.org/linux/man-pages/man7/sched.7.html I wouldn't suggest giving those permissions to your user because it opens up the possibility of a denial of service. With those permissions, any program running as your user can spawn lots of realtime threads that can take over the scheduler and lock the system up. This was detailed in the rtkit announcement, and preventing it is the reason rtkit exists: http://lalists.stanford.edu/lad/2009/06/0191.html http://lalists.stanford.edu/lad/2009/06/0191.html Maybe realtime audio is not important to you, and that's fine. But it's never as simple as "delete these things and now I have a secure system", you may be trading off security elsewhere to get that. Please also note that pkexec is not required to use polkit. You can remove pkexec and still have a functioning polkit installation and still use all those other daemons too. For a really secure system you may want to remove all suid binaries anyway and only use polkit or SELinux or something.
- trasz 5y agoSo essentially a whole another daemon/service designed to provide a fake permission system for real-time privileges?
- yrro 5y agoNothing fake about it? That is one of the actions that RealtimeKit allows clients to request: $ pkaction --action-id org.freedesktop.RealtimeKit1.acquire-high-priority --verbose org.freedesktop.RealtimeKit1.acquire-high-priority: description: Grant high priority scheduling to a user process message: Authentication is required to grant an application high priority scheduling vendor: Lennart Poettering vendor_url: icon: implicit any: no implicit inactive: yes implicit active: yes In the default configuration that will be granted to clients that are part of a local console session, but denied to clients that are not (e.g., batch jobs, SSH). That policy can be further customized by the OS vendor, organization, site, or local admin in quite a flexible way.
- mmis1000 5y agoProbably, It is used in things like NetworkManager. Which is used by almost all desktop environment. In these desktop environments. Polkit is used to gating any remote process from accessing network state related functions (or anything that are not supposed to do remotely). For example, you can use `nmcli` on the desktop or system termional(Alt+f1~f7) to disconnect the network or change to use other pppoe even you are not currently root(not using sudo to elevate the permission). But if you try to call `nmcli` through ssh? No, No , No, Polkit will gate you from doing so.
- trasz 5y agoSo why do it like this instead of simply having PAM add a group (or not) depending on ash service one is logging into, and making authorization decision based on that group?
- mmis1000 5y agoI don't think you can have different group per session?
- trasz 5y agoSure you can, see pam_group.
- yrro 5y agoGroups are not granular enough. `pkaction` lists 315 different actions on the system where I just ran it. You'd need 315 groups to begin to reflect that level of granularity... Groups are also not dynamic enough. When evaluating these rules, one of the inputs is whether the client requesting the action is a member of no session at all, or an inactive console session, or an active console session. You can't represent these with groups because you can't grant/revoke group membership to a process while it's running. (A process with a group membership can also stash away a setgid executable that can be used by the user to regain access to a group that they've been removed from later on, so it's not even possible to cast-iron-guarantee that access to a group has been revoked without inspecting the filesystem...)
- jeppesen-io 5y agoI see it with headless/gui-less Ubuntu K8s hosts; looks like from fwupd