19 ms·
Quick Tip: Enable Touch ID for Sudo (2020)
- zakk 4y agoIt’s very cool, but every update of mac OS resets it! After a while I didn’t bother to reactivate it… Is there a permanent solution, that does not involve cron scripts or other hacks?
- blinkingled 4y agoiTerm 2 password manager is a close no hacks required solution that's slightly more involved but not all that much - add your password and on sudo prompt hit cmd+shift+f, touch id and enter. The touch id part is once per iterm session so overall it's not too bad and reasonably secure as it uses built-in keychain to store passwords I think.
- inopinatus 4y agoJust go with that. Far from being a hack, converging Unix-like system configuration from scripts run out of cron is downright mundane.
- irusensei 4y agoI think there is a filesystem extended attribute that marks that file as part as the rootless system. If you exclude that attribute it might prevent it from being overwritten. I haven't tested it tho.
- 4ad 4y agoUnfortunately, this resets after every macOS update, which is very frustrating, and also absolutely ridiculous.
- ggm 4y agoNot lead pipe safe, don't think touch ID cares if your hand is attached to your body. might still do it.
- polycaster 4y agoOn the other hand: Neither does password authentication check if it were your fingers typing.
- ggm 4y agoWell played. You have your finger on the pulse.
- deleted 4y ago[deleted]
- synu 4y agoHow is your password safe from someone threatening you with a lead pipe?
- throwaway287391 4y agoI suppose if you value your privacy over your well-being/existence you can perhaps resist giving up your password (not so with a fingerprint). Or maybe you could set up a "suicide pill" alternate password that wipes/bricks the machine when entered if you wanted to deprive your future self of the opportunity to relent as the torture escalates... (Edit: I guess the latter is also doable via fingerprint if a different finger is used as the suicide pill, seems a bit risky for normal use though!)
- gattilorenz 4y ago> you could set up a "suicide pill" alternate password By... rewriting or modding sudo AND the login screen of macOS? Doesn't seem like a realistic option.
- throwaway287391 4y agoYeah it was more theoretical speculation, probably not doable on Mac (and I don't see Apple adding this feature tbh). I wouldn't be surprised if someone's implemented something like that in Linux though.
- dt2m 4y agoFor whatever reason, this resulted in me being prompted to first type my password, then also authenticate with Touch ID.
- thorncorona 4y agoThis happened to me when I didn't put the pam_tid.so line right under the first line. Mine looks like ``` auth sufficient pam_smartcard.so auth sufficient pam_tid.so auth required pam_opendirectory.so account required pam_permit.so ... ```
- dt2m 4y agoKiller, thx !
- irusensei 4y agoOrder matters. Lets say you already have a registered yubikey or similar smart card. The /etc/pam.d/sudo file might look like this: # sudo: auth account password session auth sufficient pam_smartcard.so auth required pam_opendirectory.so account required pam_permit.so password required pam_deny.so session required pam_permit.so So if for some reason you want to have both Touch ID and the smart card authentication as options you might want to do this: # sudo: auth account password session auth sufficient pam_smartcard.so auth sufficient pam_tid.so ... It will ask for smart card first but if a smart card is unavailable or authentication fails the touch mechanism will be requested. If you invert those parameters the order also gets changed.
- yuriyguts 4y agoI love using sudo with Touch ID and have been using this trick for years. The only inconvenience is that the PAM configuration always gets reverted by OS updates. I wrote a small tool to mitigate this by configuring PAM on system startup: https://github.com/YuriyGuts/persistent-touch-id-sudo https://github.com/YuriyGuts/persistent-touch-id-sudo
- rollcat 4y agoSeems like something that would be worth generalising a little bit, perhaps merge /usr/local/etc into /etc every boot? Probably could be as simple as "rsync -r /usr/local/etc/ /etc/".
- chii 4y agoyou'd want a patch file instead may be? If something new was added to /etc, you'd not want to overwrite it
- rollcat 4y agoOpenBSD has sysmerge (https://man.openbsd.org/sysmerge https://man.openbsd.org/sysmerge), Debian's dpkg will also prompt to accept/reject changes; this probably would be the ideal solution, but macOS doesn't give you an opportunity to implement such a scheme, since an upgrade just overwrites all user changes unconditionally. Patches are harder to use than plain files, since you need to maintain a source and a destination to diff against, and applying them can occasionally fail, requiring the user to resolve. I think overriding configuration in /etc is one of those cases where the user's intent is very clearly "I know what I'm doing, please get out of my way", and other unices are built to respect that. macOS assumes it's the other way around, and ends up doing crazy stuff like overwriting "PasswordAuthentication" to "yes" in sshd_config on every upgrade. Running rsync to just overwrite the configuration is probably too simplistic. Maybe the tool could detect that a file was overwritten by an upgrade, and make a backup (sshd_config.upgrade, and so on). I think I'm just going to write it now.
- 4y ago
- deleted 4y ago[deleted]
- ddlsmurf 4y agoDoesn't this block ssh (headless) access ?
- irusensei 4y agoWithin /etc/pam.d there are multiple files for each system component: authorization authorization_la chkpasswd login.term screensaver screensaver_la su authorization_aks authorization_lacont cups other screensaver_aks smbd sudo authorization_ctk checkpw login passwd screensaver_ctk sshd So if you edit the sudo file it will only affect sudo. Likewise sshd will only affect sshd. Unless of course it contains an entry that includes another file which is common for Linux. Now even if it causes problem for say sudo over ssh that page recommends that you add a "sufficient" entry. That means that method will be tried and if fails or its unavailable the next one will be tried.
- pil0u 4y agoAround 2014, I read a security researcher's article stating that biometrics should be used as an identifier at best, but never as a password. “You can change a password, but you cannot change your fingerprint”. From that day on, I’ve never used biometrics system used as authentication. With a increasing use of biometrics on phones, should I think differently in 2022?
- brainphreeze 4y agoI'd tend to agree to be honest. Consider this: a group of thieves jump you and pin you down, they want to perform a banking transaction on your phone. They grab your hand, extend your finger and press it against the phones sensor. They're in. On some mobile banking apps, they can perform the same. The use of a password only known to you cannot be physically taken from you as your mind controls that authentication mechanism.
- coding_unit_1 4y agoA $5 wrench will retrieve a password https://xkcd.com/538/ https://xkcd.com/538/ :)
- michelb 4y agoSo they beat you until you give the password.
- Sebb767 4y agoThey can also threaten to cut off your finger, in which case you'd probably want to enter the password anyway. Also, your password can easily be found by looking over your shoulder or by you unlocking your device in front of a camera - which is quite likely, given how often you unlock your phone. You can also collect and fake a fingerprint, but it's a lot more effort. On the other hand, in a few countries police can force you to use biometric authentication, but not to release your passwords. In the end, you really need to think about your threat scenario and act accordingly.
- TacticalCoder 4y agoThat's why systems correctly designed have not one but two passwords (or PINs), which look identical. You enter either and everything seems to work. But one of the two means "I'm under duress". If people home-jack me at night, my 24/7 alarm system/monitoring company calls me in the following 45 seconds at most and asks me for my password. If I say "monkey" it means everything is fine, if I say "beetle" it means I'm under duress. When I give either password, the company answers: "OK, sleep well, all is good". But in the later case they call the police and tell them a home-jacking is ongoing. (obviously my two words aren't "monkey" and "beetle", this is just an example). (as a bonus my alarm system has an anti-jamming system and communicates using several channels) Banking apps should be the same: they should have one PIN to do regular business and another one where everything looks legit, but you'd only be making fake wire transfer or only allowed tiny withdrawals, showing a small balance. Some companies (for example my alarm system) and websites (very few but I've seen some) and some HSM (for example cryptocurrencies hardware wallets can decode using two keys, one of them showing a smaller balance than the real one) have seen the light and have such a feature. I do believe we're still in the stone age when it comes to security. Most people like to post that disastrous XKCD and think the bad guys have forever won thanks to their $5 wrench. I'd hazard a guess: people thinking with that victim mentality aren't the ones coming up with better security systems.
- obert 4y ago1Password forces users to enter the master password at least every 2 weeks, super annoying and insecure. Eg my master password is super hard to enter, even more on smartphones, so I’m considering moving to a less secure one to avoid the PITA. All this technical innovation with Touch Id is great but then companies keep reverting to old annoying approaches when facing innovation…
- Sebb767 4y agoI can tell you from harsh experience that having to enter your password after a few months and struggling to remember it is strictly the worse option. It might be a PITA, but it definitely makes sense to refresh the memory once in a while.
- Saint_Genet 4y agoThat's why you write down your important master passwords.
- yosito 4y agoUnless your threat model includes someone breaking into your locked filing cabinet and stealing the post it note with your master password on it. There are some passwords that I don't write down anywhere.
- obert 4y agoI type a password to unlock my device, so I’d like having the option to use just touch Id in this case for 1Password
- nicoburns 4y agoDoes your password contain a bunch of special characters? Consider making your password consist of entirely plain english words (perhaps with a few numbers / symbols but not many) but just making it longer. That'll be just as secure and much easier to type.
- 4y ago
- urbandw311er 4y agoAm I the only one who actually finds it faster to type a password than to remove my hand from the keyboard and perform Touch ID auth?
- yallneedtogetit 4y agoyour password is too short
- zwog 4y agoNope. The only reason I work on a terminal is that I never have to take my hand off the keyboard.
- nicoburns 4y agoBut the touch ID sensor is on the keyboard!
- georgelyon 4y agoDoes anyone know why Apple doesn’t make this standard? I’ve been using this on and off for many years and only stop because I get frustrated after an OS update reverts it. Are there licensing/security/compatibility reasons this may be the case? Seems like an easy fix.
- willis936 4y agoThis is a similar project for WSL. I love it. https://github.com/nullpo-head/WSL-Hello-sudo https://github.com/nullpo-head/WSL-Hello-sudo
- pxeger1 4y agoFor people complaining that this gets reset by macOS updates, I think this should work (I haven't tested this on macOS, but it works for me on Arch Linux): 1. Copy /etc/pam.d/sudo to /etc/pam.d/customsudo and add "auth sufficient pam_tid.so" to that file instead. 2. Create the directory /etc/sudoers.d/ if it does not exist 3. Create the file /etc/sudoers.d/customtouchid with the following content: Defaults pam_service=customsudo You may need to set the right permissions on /etc/sudoers.d/customtouchid before sudo will accept it.
- nicwolff 4y agoI did this and set perms on /etc/sudoers.d/customtouchid to 0444, now `sudo` opens the dialog, but touching the Touch ID gets sudo: account validation failure, is your account locked? sudo: a password is required
- hsbauauvhabzb 4y agoI lock my computer when not near it. If my computer is breached, having user level access of the one account permitted sudo is pretty much Crown Jewels. If you really wanted to privesc you could sniff X11 keystrokes or back door bashrc, but either way even user level access screws me so whatever do what you want after that. As a result, I just enable passwordless sudo.
- rollcat 4y agoYou're right, once an adversary gains physical access (or even remote access as your main login account), all bets are off. This is the area where the traditional UNIX security model has failed to adapt at all: you need a password to install a random game from apt (a vetted and trusted source), but you don't need a password to install a cryptolocker, or exfiltrate personal data. However I like having a password (or some other form of confirmation), just so that I can stop to think for a second, whether what I'm about to do is a good idea. What's annoying is that I effectively need two different policies on workstations and on servers, since I still want to be able to escalate privileges from maintenance scripts[1]. [1]: https://github.com/rollcat/judo/issues/9 https://github.com/rollcat/judo/issues/9
- PureParadigm 4y agoI do the same. I've yet to hear a convincing argument against this practice. Everyone seems okay with passwordless docker and you can use that to privilege escalate too.
- hsbauauvhabzb 4y agoI use FDE so I’ve also configured gdm3 to auto login, login and screen lock are two separate concepts and I only use the latter :)
- deckard1 4y agoyep. What I did in the past, back when yubikey first came out, was I added a PAM module to check the presence of the yubikey. It's almost comically stupid since it just checks that the key is inserted with the correct serial number. But you'd need root to see what the number is (to emulate it with a fake usb device, I guess), and to get sudo you'd need the key inserted. I WFH so I'd just leave the key inserted for passwordless sudo all the time. But if I needed to step out, just grab the yubikey and go.
- haunter 4y agoThis is what I'm trying to do but under Windows and Debian + preferably with a mechanical keyboard. Well the mechanical keyboard w/ fingerprint reader is the bigger ask cause there aren't many choices. There is a decently good one with Cherry MX switches from Taiwan but pretty much impossible to order one to Europe (they sell their other keyboards but not the one with fingerprint reader) https://www.i-rocks.com/web/product/product_in.jsp?pd_no=PD1550820469030&lang=en https://www.i-rocks.com/web/product/product_in.jsp?pd_no=PD1...
- TacticalCoder 4y agoWhy not a FIDO key? The most stupid ones work with just a click (but they do work and they're cheap, so there's that). Then there are slightly less dumb ones that works with your fingerprint. Then there are less stupid ones which are using a PIN to register a new service and another PIN to authenticate yourself to a previously registered service.
- jeroenhd 4y agoIt's not exactly the same, but you could try to buy a keyboard with a USB port on the back and add a USB fingerprint reader (i.e. https://www.kensington.com/p/products/data-protection/biometric/verimark-fingerprint-key-fido-u2f-2nd-factor-authentication-and-windows-hello/ https://www.kensington.com/p/products/data-protection/biomet...) that way. You'd have a little "key" dangling off the back or side of your keyboard and you'd be "wasting" a USB port on your fancy keyboard, but it'd work to get a fingerprint reader close to your hands on a desktop.
- haunter 4y agoThanks I like this, didn't even think about it!
- fastball 4y agoIf you want to do the same but auth with your Apple Watch, you can follow this[1] guide. [1] https://akrabat.com/add-apple-watch-authentication-to-sudo/ https://akrabat.com/add-apple-watch-authentication-to-sudo/
- Reason077 4y agoSimply adding pam_tid.so, and turning on Apple Watch authentication in System Preferences, enables Watch authentication in sudo on macOS Monterey. No need for the third party pam module!
- fastball 4y agoOh huh, you're right. That's so strange, I tried that originally but it didn't work for me.
- duplabe 4y agoI think it's a much better guide with iterm support: https://austencam.com/posts/using-touchid-with-sudo-in-terminal-or-iterm https://austencam.com/posts/using-touchid-with-sudo-in-termi...
- unpopularopp 4y agoI didn't know that module was open source! https://opensource.apple.com/source/pam_modules/pam_modules-186.60.1/modules/pam_tid/pam_tid.c.auto.html https://opensource.apple.com/source/pam_modules/pam_modules-...
- jdthedisciple 4y agoSurely very convenient but idk, I still feel a li'l icky using my fingerprint for authorization. What if one day the fingerprint sensor acts up a little, as can always happen with such sensitive hardware? Then you 're just completely screwed?
- josu 4y agoNo, you just use the password.
- jdthedisciple 4y agoWhat? So there's no added security by using TouchID as some here seem to think? So it's a pure convenience thing ... if so then well, I'm personally not very annoyed by having to enter my password when my hands are on the keyboard anyway.
- JW_00000 4y agoI think the idea is that you can choose a very long and complex password, because you won't have to enter it so often once you enable TouchID. Without TouchID, most people are tempted to choose passwords that are easy and quick to type.
- yrro 4y agoDepends how you configure PAM. You can have it set up so you need both touch and password if you really want...
- FabHK 4y agoAs the article says (my highlight): > That line basically tells the sudo command that the Touch ID authentication module is sufficient to authorize the user
- dingleberry420 4y agoTitle should mention "mac tip"
- jeroenhd 4y agoWell, `sudo` is a *nix binary, so Linux and macOS are your most popular options here. Fingerprint authentication for sudo was enabled by default on my Manjaro install after I enrolled a fingerprint so I guess popular Linux distributions configure it automatically. If yours doesn't, try the configuration methods on this page: https://wiki.archlinux.org/title/fprint https://wiki.archlinux.org/title/fprint or here: https://askubuntu.com/questions/1015416/use-fingerprint-authentication-not-only-for-login https://askubuntu.com/questions/1015416/use-fingerprint-auth... or consult your operating system's documentation. The big difference is that you need "pam_fprintd.so" instead of "pam_tid". On Ubuntu (or derived, probably), running "sudo pam-auth-update" will allow you to configure fingerprint authentication without needing to manually edit system files. Do note that if you use a more exotic window manager, any fancy visual sudo prompts may not know how to deal with such a system. I don't know how gksudo and i3 work together on this, as visual sudo tools often try to block access to other windows. If you're on Windows and want WSL with Windows Hello, there's this tool: https://github.com/nullpo-head/WSL-Hello-sudo https://github.com/nullpo-head/WSL-Hello-sudo which is a PAM library that will call into Windows Hello from WSL. Windows Hello should in turn support your fingerprint reader or other biometric authentication system configured for your PC.
- corderop 4y agoAm I the only one that things I write my password faster than putting my finger in the Touch ID?
- polycaster 4y agoPerhaps your password is too short.
- franga2000 4y agoI'm not doubting your speed-typing ability, but if you can actually do that, it just means your password is too short
- paulcole 4y agoITT: “Ackshully if your threat model includes James Bond level tradecraft this is a bad idea.” Spoiler alert: Essentially nobody’s threat model includes that.
- Reason077 4y agoThis is pretty neat. But one annoyance is that on macOS Monterey, the authentication pop-up dialog doesn't have focus when it appears. You first need to click on it before you can use Touch ID. That slows the whole process down to the point where it's probably just quicker and easier to use your password. Is there any way to make the pop-up automatically get focus, or is that itself a security risk somehow? (Side note: the same module enables authentication by Apple Watch too! But again, having to take your hands off the keyboard to tap the Apple Watch to approve the request slows down the process so much that it's hardly worth it)
- edjw 4y agoI find that the dialog pops up without focussed when I launch Bitwarden, but does have focus when I launch 1Password. It is confusing
- Rygian 4y agoIf anything, the reverse is a security risk: applications that steal focus while I am typing down a password.
- wonderbore 4y agoSoftware stealing focus is an awful antipattern and I wish macOS would fix this crap. Even on iOS, which is otherwise good with this, will gladly interrupt whatever you’re doing to show you a fullscreen captive portal. Obnoxious, especially if you’re just walking by an open wifi you joined at some point in your life.
- Mindwipe 4y agoIt completely baffles me why captive portals do not obey the normal windowing mechanisms on iOS.
- easton 4y agoBecause then the average user would say "I know I'm on Wi-Fi because Control Center says so, but nothing loads in {app that isn't a browser}". Or worse, "I joined a Wi-Fi network but my iPhone decided that it can't connect to the internet through that so now it's using my data plan instead without telling me[0]". Windows and macOS pop up the default browser (or on macOS, a webview) with the captive portal when they detect one. iOS doesn't have windows, so if it wants to get the user to do the captive portal without them sitting there in confusion it has to pop it up. It could pop a notification, but if the user misses it (as one could, with all the notifications that come in these days), then they are stuck. 0: https://support.apple.com/en-us/HT205296 https://support.apple.com/en-us/HT205296 (which has kicked in for me sometimes when my LAN doesn't have internet for whatever reason)
- delogos 4y agoSpeaking from personal experience, don't do this on a machine you'll ever access remotely, because then you're stuck waiting for the biometric check to time out before you can authenticate via another method.
- bodge5000 4y agoDoesnt just apply to macs/touch bar either. Had the same issue when I setup my fingerprint sensor on my thinkpad on fedora. Maybe theres a way to get both to work, but I never found it
- jwr 4y agoThat's why I prefer using Yubikeys (using this setup: https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide) — and this method times out immediately (just press esc when the "insert card" dialog comes up). Plus you can have multiple keys. Plus you can use them for gpg and ssh. Plus you can back them up. Plus you can print them on paper.
- tirwander 4y agoThe biggest reason I haven't adopted Yubikey yet is that I'm super worried I'll lose that one little USB/NFC key
- vhiremath4 4y agoCall me old fashion, but I love the feel of entering my sudo pw. It’s the rumbling to my v8 engine. I mean M1 Mac.
- wrexx0r 4y agoSo I've run into issues with this in the past, which seems to relate to using DisplayLink. Seems to be in how MacOS treats the DisplayLink driver, and can't be fixed unless Apple makes some changes in the OS level
- woodruffw 4y agoIf you're like me and you got the order wrong, this will completely break your PAM configuration. To fix it, I had to temporarily enable the actual root user[1]. [1]: https://superuser.com/a/1357253 https://superuser.com/a/1357253
- nimbius 4y agoreminder: biometrics are not protected by the fifth amendment. use strong passphrases. https://www.eff.org/dice https://www.eff.org/dice
- eatmyshorts 4y agoIs there any way to do this as a 2nd factor, so that both my password and my fingerprint are needed for sudo?
- cbxyp 4y agoidk if the pam module used to be around but i remember building a modified sudo binary to accomplish this on my MBP pro a few years ago.
- CalRobert 4y agoFingerprints are usernames, not passwords - related discussion (from 2013!) https://news.ycombinator.com/item?id=6477505 https://news.ycombinator.com/item?id=6477505
- deleted 4y ago[deleted]
- saxonww 4y agoI've tried this multiple times over the years and it doesn't seem to work, at least not with tmux.
- er0k 4y agothis works for me with tmux https://github.com/fabianishere/pam_reattach https://github.com/fabianishere/pam_reattach
- mshockwave 4y agoI tried this a couple of years ago but it would be reset after every system upgrades. Is it still a case now?
- likecarter 4y agoShortcut: echo 'auth sufficient pam_tid.so' | sudo tee -a /etc/pam.d/sudo
- DavideNL 4y agoFor some reason, this only seems to accepts my Apple Watch as authentication, but not the fingerprint sensor... any idea why? (fingerprint works to authenticate in System Preferences, etc.) $ cat sudo # sudo: auth account password session auth sufficient pam_tid.so auth sufficient pam_smartcard.so auth required pam_opendirectory.so account required pam_permit.so password required pam_deny.so session required pam_permit.so