3 ms·
I see touch ID for sudo as the equivalent of 2FA. I am on my computer, I'm logged in in the account that has admin permissions but we want to confirm that it's
by gommm 4y ago
I see touch ID for sudo as the equivalent of 2FA. I am on my computer, I'm logged in in the account that has admin permissions but we want to confirm that it's me and not someone else that is logged in to my account, so touchid for sudo acts as a 2fa.
- leksak 4y agoThat's a fine 2FA unless your threat model involves physical coercion. The nice thing about passwords is that giving it is, with the exception of some drugs maybe, voluntary. You don't really have the same agency if someone forcibly makes your finger touch the device. And I think fingerprints work even on a dead body. And can be lifted from inanimate surfaces like a glas at a bar.
- prvit 4y agoThis feels ignorant of the fact that all the interesting information on your computer will be accessible without sudo. touchid is actually better than a password here, as it prevents malware from using sudo without physical confirmation from you.
- jonfw 4y agoWhat do you expect you will do if somebody capable of killing you wants your password? I can't imagine a circumstance where I would not voluntarily give somebody a password if they were in a position to physically force me to provide biometrics