5 ms·
That seems pretty stupid. While they're at it, why not update the SSH warning banner with a list of what we do and don't log on this system. As a courtesy to t
by john_shafthair 3y ago
That seems pretty stupid.
While they're at it, why not update the SSH warning banner with a list of what we do and don't log on this system. As a courtesy to their adversary.
This sudo message has been the same since the dawn of time. There is literally no reason to correct it. This is the one place you don't want to be pedantic, leaking security configuration via stderr.
- deleted 3y ago[deleted]
- kragen 3y agosomething like 99% of computers with sudo installed are single-user machines where the only effect of the warning is to scare people and it's only been the same since people started to switch to sudo in the late 90s; su never printed such a warning
- TaylorAlexander 3y agoReminds me of when I was younger and my mom and my brother were using a windows computer. They got the message “an illegal error has occurred” and my mom called me to ask if they had broken the law.
- mr_mitm 3y agoWhen I was young I had messed with the computer and it showed an english message with the word "atom" in it. My mom not being a native speaker freaked out as if a nuclear explosion was about to take place.
- Gigachad 3y agoI almost shit myself the first time I saw X Screensaver.. It has to take the prize for worst UX ever.
- kragen 3y agodo you mean the bsod screensaver sometimes people also complain about xscreensaver's lock screen because it doesn't use a widget library, but the alternative lock screens can often be crashed through bugs in the widget libraries they use
- Gigachad 3y agoThe one with the flaming screen and countdown timer. I had just installed the distro and though I had some malware installed.
- kragen 3y agooh, that's just the lock screen the flaming screen is just the xscreensaver logo (it's supposed to save your screen from burnin, originally) i hadn't ever heard of anyone thinking it was malware, that's pretty funny jwz is a more brilliant troll than i gave him credit for
- john_shafthair 3y ago[flagged]
- Arch485 3y agoI don't really think this is a security issue. If an attacker is able to try executing sudo on your system, you have much bigger problems (for example, data exfil can be done by non-sudo users in many cases, or if your system is sufficiently old there's known priviledge escalation exploits). I don't think an attacker gains much knowledge from knowing whether or not they're on the naughty list.
- IshKebab 3y agoIf the attacker can execute sudo they can probably just alias it to a sudo that sends them the password and wait. The number of users on multiuser systems who don't have sudo access is just vanishingly small. Universities perhaps. But in most companies, if they trust you with access to the machine in the first place they'll trust you with sudo access.
- alexb_ 3y ago>the only effect of the warning is to scare people Good. If you're not familiar with what sudo does, then you shouldn't be using it in the first place.
- kibwen 3y agoIf you shouldn't be using sudo, then you shouldn't be listed as a sudoer on that system. If you're listed as a sudoer, then you should become familiar with what sudo does.
- pxeger1 3y agoIt's an abstraction. You shouldn't need to be familiar with every aspect of what it does.
- teaearlgraycold 3y agoIf it’s your own computer you should be able to break it until you learn how not to.
- twelve40 3y agoi'd argue in a different direction: if sudo barks a scary unknown message at me, i'd avoid using it altogether and just use su, which is the opposite of what people should be nudged to do.
- kaba0 3y agoAre you familiar with every part of the stack you are working on, down to the hardware?
- salawat 3y agoYes. Largely through torturing my system and reducing it to non-bootable state and having to read up on what symbols I mangled this time and how. Why do you ask?
- discreditable 3y agoWarning banners are not uncommon. https://www.stigviewer.com/stig/red_hat_enterprise_linux_8/2021-06-14/finding/V-230225 https://www.stigviewer.com/stig/red_hat_enterprise_linux_8/2...
- microtherion 3y agoMaybe update pnews.sh as well to recalibrate the estimate of "hundreds, if not thousands of dollars" per usenet message.
- aflag 3y agoThat message is poor UI. If you know what it means, you probably don't care about the possibility of sudo sending an email when you first typed it. If you don't know, you will be worried probably without a good reason to be so. Nowadays it's even worse than it once was, because now the natural instinct of people is to think that the incident was reported to canonical or ibm. The opposite of how they are supposed to feel about when using free software. I'd change it to "This attempted was logged" or something like that when that is true. Just so the user is aware that the data they are typing there may be seen by someone else. But by default, in their own systems, that message should never appear, unless they specifically configured it that way.