14 ms·
Why GNU su does not support the `wheel' group (2002)
- bell-cot 3y agoReaction: Mr. Stallman's idyllic worldview does not seem to admit that someone may actually own the computer system in question, or otherwise have legal rights to set limits on who uses the system, when, and for what purposes. And what was allowed by the social norms of the tiny 1980's *nix computing world, or what you can get away with when you're as famous as Mr. Stallman...those may not translate well to other contexts.
- voz_ 3y agoI can’t stand his holier than thou writing. No amount of brilliance or clever code makes someone less of an asshole.
- rvnx 3y agoSome people are so dazzled by singing and dancing skills, that they consider their singer to be a hero and a nice guy. Similarly, Stallman's coding expertise can sometimes overshadow any potential shortcomings in the non-IT subjects.
- mcpackieh 3y agoPersonally, I'm dazzled by Stallman's singing and dancing skills. Join us now and share the software, You'lll be free, hackers, you'll be freee Also by his uncanny tendency to be proven correct in matters concerning software freedom. His coding expertise are tertiary at most. Honestly, I never see people praise RMS's coding expertise, where are you even getting that idea from? I don't think you get it why people like RMS.
- rvnx 3y agoYou just pinpointed the problem. He is good at one domain, and then by cognitive bias people think he is right on everything. It’s not true at all, and I think you have to take a bit of distance with glorifying IT personalities. Like Bill Gates, Elon Musk, Stallman, and many others (especially in the VC world) it’s important to take them with a grain of salt, and not accept them as perfect nice guys because they have money (Musk) or influence (Stallman). Otherwise they can spread dangerous ideas that normally should 100% be challenged, but that are not, due to blind acceptance.
- mcpackieh 3y ago> He is good at one domain, and then by cognitive bias people think he is right on everything. You really don't get it at all. You're out of touch. People think that Stallman is right about one thing only, software freedom, and think he's out of touch with virtually everything else.
- rvnx 3y agoWell we actually somehow agree, but for different reasons. It's good, for a second I thought you were supporting his views on non-IT topics. The problem is that the political speeches are part of the person, and the scope way way beyond software. They are really interleaved with (supposed) IT topics, like if IT was a bait. Once I went to one of his conference, and I had "learnt" more about "sex" and "facism" than software engineering or freedom.
- hackan 3y agolegal rights? "I'm on the side of the masses, not that of the rulers." He is pretty clear...
- bell-cot 3y agoReaction: How does that ideal play out, when a few kiddies start running fork bombs on a *nix system that Mr. Stallman wants to use?
- thriftwy 3y agoFork bomb does not need root to function.
- berbec 3y ago:(){ :|:& };: explodes fine as a regular user
- TillE 3y agoOnly if you haven't configured sane limits.
- NoZebra120vClip 3y agoThis actually went on for many years. rms famously refused to secure his account @gnu.ai.mit.edu, and so the machine basically became an open shell server for every hacker in the world, ca. 1992. Lots of hijinks ensued, and it was usually not possible to do anything useful in that account, since it was usually broken or pwned in remarkable ways. But they were wild, fun times.
- segfaultbuserr 3y agoIn a similar vein, EFF cofounder John Gilmore famously refused to secure his SMTP server at toad.com [1]. He believed SMTP should be open for all just like the old days, potentially making it basically an open relay for every hacker and spammer in the world. And so, he got into trouble with his ISP. Gilmore said the server was in fact rate-limited and the abuse potential was not as large as it appeared to be. [1] https://en.wikipedia.org/wiki/John_Gilmore_(activist)#Activism https://en.wikipedia.org/wiki/John_Gilmore_(activist)#Activi...
- ye-olde-sysrq 3y ago> If you are used to supporting the bosses and sysadmins in whatever they do, you might find this idea strange at first. Should this be that far-fetched though? That employees might not be simple thralls of the capitalist, whose agency extends only as far as his master permits? It reminds me of something I'd read that one of the reasons modern capitalism is so borked is because the founding fathers weren't conceiving of things like "Amazon" existing, where one entity employs a staggeringly large number of employees. Or that a small number of companies would employ such a large percentage of workers. Their worldview was that where most people were "self-employed" - and if they weren't, employers were small and had a few or tens of employees at most. Or it was a matter of master and apprentices where both groups were investing heavily in each other in a trade and in the running of a shop. So, while yes our current system finds it a matter of course that employees are utterly subject to the whims of their employer and the legal and economic system fully supports them in this, does it have to be that way? (I know you can go be a contractor, but good luck with health insurance and etc etc etc all the other things that being yoked to an employer brings that I wish were just public taxpayer-funded services).
- aquova 3y ago> It reminds me of something I'd read that one of the reasons modern capitalism is so borked is because the founding fathers weren't conceiving of things like "Amazon" existing, where one entity employs a staggeringly large number of employees. Or that a small number of companies would employ such a large percentage of workers. I'm not quite sure I buy that argument. They lived in the time of the East India Company, which owned something like 50% of the world's trade at the time and ruled several nations.
- ye-olde-sysrq 3y agoYeah, there's definitely counterexamples. I thought of East India too. I really wonder what operating a huge company like that looked like in an era where the fastest way to transport messages was to have fresh horses pre-positioned every X miles and have someone gallop your message non-stop. I assume it was very different from Amazon employees peeing in bottles to avoid getting dinged for metrics.
- gorjusborg 3y agoIt does seem a very strange position when today's sensibilities are applied. I do understand the point of view when I think back. Today, Unix-like systems are everywhere. Learning it and working with it is a given. Back then, having access to a unix system was not a given. It was very expensive for hardware and software. The idea that one would be so close to the system and could be denied enough access by an overzealous BOFH was too much to take. It just goes to show that circumstances change, and things can get weird if we don't change with it.
- nisegami 3y agoLegal rights are not moral rights.
- nightpool 3y agoCompare to https://news.ycombinator.com/item?id=37173339 https://news.ycombinator.com/item?id=37173339 which has a lot of discussions of similar issues for "modern" security configurations. Just because IT admins can choose to set a short session expiration on your SSO integration for your MDM managed laptop doesn't mean that we should cooperate with them or develop tools to let them do that.
- seabird 3y agoStallman's ideas are often informed by high trust environments and business arrangements where the cost of the software itself is a fraction of the TCO. There's a big disconnect between the environment where Stallman made up his mind (large education/business environments) and how most people are introduced to free software (low cost entry into technical computer usage). I used to think Stallman was an ideologue from a different era. When I started dealing with software projects measured in years and millions his thoughts made much more sense to me. When you're selling me a system that has a 6/7 digit implementation cost for it to stand any chance of meeting my goals, withholding the source code only serves to annoy me.
- Dylan16807 3y agoWithholding source code is obnoxious in any era. But that's a pretty distant issue from administrative privileges.
- seabird 3y agoNon-administrative users are given administrative privileges to complete their work all the time, even today. Misuse results in them being disciplined or fired. Heavy-handed privilege controls are very often a drain on the productivity of users and can result in stupid or dangerous (from a security standpoint) workarounds. 20 years on, you have to exercise more judgement in what you allow considering modern risks, but the idea that you shouldn't make things harder for people over a small number of bad actors that you can handle at an organizational level is still a good one.
- treffer 3y agoWell, I am a bit unsure if it does or does not translate well.... One of my favorites is extensive rights management. Especially on CMS. More ofte than not it is part of a buying decision, but used Stallman style soon after. The observation that these credentials leak is correct. Or that you grow permissions over time for no other reason than doing work. A wheel group would today quickly attract users, too. So let it be. The latest iteration is "basically let everyone, but audited and short term only". I find that very close to Stallmanns idea, for very different reasons.
- indymike 3y ago> someone may actually own the computer system in question, And that person may not be the systemadmin
- nine_k 3y agoIt shows how old is that, and how things changed. Back in the day, it was about multiple OS users on one big machine, maintained by a university or a corporation. Now I'm the only human user of my several machines. I have more than one interactive user account on some of them. I put these accounts to the wheel group, to avoid ever using a root password. (Void Linux has it pre-configured in /etc/sudoers.)
- jml7c5 3y agoYes, Unix was designed to protect users from each other but the modern need is to protect applications/invocations from each other. It is unfortunate that Unix wasn't really designed for the modern use case. Basically https://xkcd.com/1200/ https://xkcd.com/1200/
- fsflover 3y agoThe solution is to use https://qubes-os.org https://qubes-os.org. My daily driver, can't recommend it enough.
- bee_rider 3y agoQubes is one of those things that, I think, everyone knows is better but it seems just far enough away to not want to change. How big of a change is it? If you are, say, a Linux terminal native can you just pick up and run?
- heisstupid 3y agoWhat a great example of how slavish devotion to an ideology makes idiots out of smart people.
- oasisaimlessly 3y agoThat's just like, your opinion, man.
- dataflow 3y agoI read the page and don't understand what's going on. What is special about the 'wheel' group and what is su even "checking" in the first place? Isn't it just supposed to switch user? And what are the implications of not-checking whatever it was supposed to check? And I also don't get: if someone has the root password, can't they change what groups they're a member of?
- klodolph 3y agoBasically, su vs sudo. Do you want any user to be able to become root, if they know the root password? Or do you want more control over the process?
- segfaultbuserr 3y ago> What is special about the 'wheel' group and what is su even "checking" in the first place? By convention, "wheel" is a special Unix user group that determines who can use "su" and "sudo". Most "su" and "sudo" implementations allow the sysadmin to make their use exclusive to the trusted users inside the "wheel" group. In most systems, it's the default setting of "su", and optional for "sudo" (given as an example in /etc/sudoers). > if someone has the root password, can't they change what groups they're a member of? No. If "su" is configured to be "wheel"-exclusive, you can't log in as root even if you have the password, because you cannot use "su" - unless you have direct access to the system console that allows you to type "username: root", which is almost never the case on servers that disable remote root login.
- deleted 3y ago[deleted]
- cperciva 3y agoWhat is special about the 'wheel' group and what is su even "checking" in the first place? Users who aren't in the wheel group aren't supposed to be able to become root, even if they have the password. Isn't it just supposed to switch user? And what are the implications of not-checking whatever it was supposed to check? Someone who steals the root password (say, by looking over the sysadmin's shoulder) would be able to become root. And I also don't get: if someone has the root password, can't they change what groups they're a member of? No, because they can't log in as root and (on non-broken systems) can't become root.
- rvnx 3y agoThere are little (to no?) situations where su has a good reason to check wheel. You either have the password, or you don't have it. But not something in-between. Outside of any ideology, in a scenario where you use su to become root, it's a very odd choice to link the wheel group to su; because if you know the password to the "root" user, and you have physical or remote access to the computer, you can likely just login as root. And if you can't, then it means you actually needed sudo su, not su. Those who actually need to be root, usually use sudo instead of su. In the other cases, if you just need to switch user, then no point at all to refer to wheel
- klodolph 3y agoYou can disable direct root login and force users to login as their own account first. This way, any root login is tracked—you know who logged in as root, because they had to log in as their own account in order to run su.
- rvnx 3y agoIn such case: sudo su, then. and let sudo verify that the user belongs to the group of allowed sudoers. No need for the password to the root account.
- rollcat 3y agoObjection: su is a very simple program that does (approximately) one thing. Meanwhile the sudoers(5) man page starts with an introduction to EBNF grammars. I strongly prefer doas wherever it's available.
- rcxdude 3y agosudo does completely obselete su, yes. (sudo su is redundant, you can just sudo -su)
- tux2bsd 3y agoincorrect, they serve different purposes. If sudo isn't installed then you don't require security updates for sudo... If you do have sudo you can be very restrictive on who can run what.
- dale_glass 3y agoTo be fair, that's ancient. This links to coreutils 4.5.4. I've got 9.1 installed. The current manpage says support for wheel is implemented in PAM.
- e28eta 3y agoI found this patch, which adds PAM support to coreutils 5: https://lists.gnu.org/archive/html/bug-coreutils/2003-04/msg00031.html https://lists.gnu.org/archive/html/bug-coreutils/2003-04/msg... It removes the section at the bottom of the man page, and has this addition to the source code comments: +#ifdef USE_PAM + + Actually, with PAM, su has nothing to do with whether or not a + wheel group is enforced by su. RMS tries to restrict your access + to a su which implements the wheel group, but PAM considers that + to be fascist, and gives the user/sysadmin the opportunity to + enforce a wheel group by proper editing of /etc/pam.conf + +#endif
- dathinab 3y agoA different reason why it's good that it doesn't support wheel: - it makes it smaller, less code which can go wrong - su isn't limited to "set user root" but wheel tends to be - it avoids having to handle many kind of subtle problems with group based permission handling in linux It's just not a bad idea to have a very minimalist program like su and then delegate all more complicated "acting as user" permission handling to other programs like sudo or doas. Through tbh. the more I do learn the more I come to believe that uid/gid based permission handling is fundamentally flawed (but also good enough inside of a single application OCI(docker) image). The facts that Linux had to add a (very limited) capability system or that enterprise permission handling often goes through stuff like pollkit adding additional handling then just "gid/uid match" is I think very telling.
- vbezhenar 3y agosuid bits are flawed and ideally should not exist. You should only be able to drop privileges. su/sudo should be replaced by ssh anotheruser@localhost (or simpler implementation with unix socket and without encryption, but the idea is the same).
- chasil 3y agoYou would not be able to change your password without suid. I guess there are ways that sudo/doas could be adapted to implement passwd, chfn, chsh and friends, but the approach appears to have been chosen in the '70, and codified by POSIX. How do you think these should be implemented?
- vbezhenar 3y agoJust make a request to the service which runs under root to change password. Include necessary credentials (e.g. current password or its hash) and new password (or its hash). How this request will be authenticated is another matter, but there are plenty of ways to authenticate a request. Or may be there should be better ways if current ways are flawed. My point that it does not have to be coded in the kernel as a dedicated mechanism to circumvent protection. Use any IPC channel to send a message to another process which already runs under root and accept those messages.
- IshKebab 3y agoThis sounds like a protest against someone not giving him the root password. A stupid protest.
- tux2bsd 3y ago[dead]
- e28eta 3y agoI’m curious how Twenex worked, that a non-operator (root) account was able to patch the kernel. Maybe the kernel files were unprotected, because it’d be absurd for ordinary users to want to change them? Or did he have to use an exploit to elevate his privileges?
- pram 3y agoProbably just didn't have filesystem permissions of any kind.
- pram 3y agoDoes this mean that RMS is ideologically opposed to sudo?
- jrockway 3y agoMaybe. You still only have to learn one password under each system. If someone named foobar sympathizes with you and leaks their password, then you login in as foobar and "sudo bash" or whatever. The way RMS envisions is that the root password is shared among many people and one of them shares it with you (there is no way to know who), and then you use your own account to "su" and use the root password. It's easy to get someone in trouble in either case. If the user foobar starts doing crazy stuff as root, then foobar is in trouble. If you get the root password and start doing crazy stuff, then your username is associated with the troublemaking. (Assume that the logs go to some machine where you don't have access to remove them.) RMS's mechanism shifts the responsibility for your actions onto you, so that someone who knows the root password is more likely to leak it to you. The best of both worlds is to get the root password, then find a hapless coworker who left their screen unlocked while out to lunch. su with the root password there, cause your chaos, everyone blames lunch guy. (Do look for outside systems; people and cameras can see you using someone's computer. Was always funny to me how many people have tried something like this, only to be nailed by the security cameras.)
- ilyt 3y agoThat doesn't make any sense ? Why it should check some random group ?
- marcus0x62 3y agoThe idea is to only allow user accounts in the wheel group to invoke su to take on root privileges. So, if someone had access to a random user account and knew the root password it wouldn’t do them any good.
- jortr0n 3y agoHere's an video of RMS talking about the period referenced in that man page regarding the introduction of passwords on user accounts: https://youtu.be/k0RYQVkQmWU?t=235 https://youtu.be/k0RYQVkQmWU?t=235
- twoodfin 3y agoThe etymological history of the group name is interesting: https://en.wikipedia.org/wiki/Wheel_(computing) https://en.wikipedia.org/wiki/Wheel_(computing) The term wheel was first applied to computer user privilege levels after the introduction of the TENEX operating system, later distributed under the name TOPS-20 in the 1960s and early 1970s. The term was derived from the slang phrase big wheel, referring to a person with great power or influence. In the 1980s, the term was imported into Unix culture due to the migration of operating system developers and users from TENEX/TOPS-20 to Unix.
- somat 3y agoI always understood it as the thing you use to drive the ship.
- unsignednoop 3y ago[dead]