4 ms·
The alternative, which is Linux, is to grant your calculator app the permissions to read and write to the same resources that your browser uses to store the pas
by lazyier 4y ago
The alternative, which is Linux, is to grant your calculator app the permissions to read and write to the same resources that your browser uses to store the password for your bank.
Well "grant" is too strong of a word. "By default and there is nothing you can do about it unless you are exceptionally skilled" is more accurate.
Also your calculator app can read your sudo password as you type it, which you do a dozen times a day to carry out complex and security sensitive tasks such as "Connect to printer to print out mom's recipe for brownies" and "restart bluetooth because it's buggy and you want to listen to spotify on your wireless headphones".
- vaylian 4y ago> Also your calculator app can read your sudo password as you type it True with X11. Fixed in Wayland.
- htkibar 4y agoWhich is still not the standard - probably will take at least a decade before we can even talk about this issue being fixed.
- johnny22 4y agostandard or not, it's already shipping by default in ubuntu and fedora except for when nvidia drivers are involved. The problems will be worked out.. one way or the other.
- yyyk 4y agoWayland fixed one problem, but there's no shortage of local privilege escalation bugs with which the calculator can still read the sudo password.
- vaylian 4y agoI want to learn more. Do you have some examples?
- yyyk 4y agoJust yesterday, Microsoft found a few[0]. There's no shortage of these, but more important is the haphazard way fixes are backported to longterm (e.g. [1]). This reached the point that Google's security advice is 'always follow the latest kernel'[2], except most users and distros simply cannot afford it, so they are stuck with a vulnerable system. Linux is not unique here. In the longterm, all the typical desktop OSs will need significant structural changes far beyond 'chase vulnerabilities and patch everything all the time'. [0] https://www.theregister.com/2022/04/27/microsoft-linux-vulnerability/ https://www.theregister.com/2022/04/27/microsoft-linux-vulne... [1] https://nvd.nist.gov/vuln/detail/CVE-2019-15902 https://nvd.nist.gov/vuln/detail/CVE-2019-15902 [2] https://security.googleblog.com/2021/08/linux-kernel-security-done-right.html https://security.googleblog.com/2021/08/linux-kernel-securit...
- freeopinion 4y agoOh, I agree. I'm just noting that access controls are useless in a culture that ignores them. I think that goes for the original topic of SELinux.