4 ms·
Having so many different feeatures in one of the most basic unix tools is much more of a red flag.
by dtx1 3y ago
Having so many different feeatures in one of the most basic unix tools is much more of a red flag.
- garblegarble 3y agoFor sure! But that mistake has already been made, and has been in the wild for years, so removing those features (and proposing yourself as a replacement for the original) is now a breaking change
- mprovost 3y agoOpenBSD replaced sudo with doas (with a vastly reduced feature set) several years ago, and without breaking everything. Sure there are use cases where you absolutely need some feature of sudo, but you can always install it.
- garblegarble 3y agoThat seems like the Right Way to do it... As annoying as it is to have to update every sudo reference -> doas, it forces you to think about everywhere you're using it, rather than waiting to see what breaks and then trying to fix it.
- codetrotter 3y ago> As annoying as it is to have to update every sudo reference -> doas, it forces you to think about everywhere you're using it, rather than waiting to see what breaks and then trying to fix it. In my scripts I never call sudo or doas. Instead, if the script needs to do something as root, I write the whole script so that it expects to itself be run as root. And then when I want to run my script, I run it as root doas ./somescript.zsh
- PrimeMcFly 3y agoThat's a much worse approach from a security pov.
- codetrotter 3y agoNo. That’s a blanket statement on your part that you cannot make because you don’t know what my scripts look like, or what commands they call.
- xyzzy_plugh 3y agoNo, it's never better to run whole scripts as root when root is only required for part of it. Unless every expression in your script requires root, the blanket statement holds. In my experience, and in my own scripts, it is better to explicitly check if you are being run as root, advise against it and exit (with maybe some break glass flags) and invoke sudo when escalated privileges are required.
- PrimeMcFly 3y agoYes, it's a blanket statement, better it's an absolute statement because it's absolutely true. You're taking a shortcut due to convenience and it's bad security practice. It's that simple.
- josefx 3y agoI just constantly run as root since there is always a chance that I might need root permissions for something. /s
- deleted 3y ago[deleted]
- samus 3y agoOpenBSD is much more open (pun not intended!) about breaking parts of userspace to push through beneficial changes. After all, they control their own userspace and can fix up most things before they even become an issue. Linux is only the kernel.
- cpach 3y agoIn that case, shouldn’t Linux distros be even more free to break things…? In theory they can bundle any userland tools they want. AFAIK sudo isn’t really tightly coupled to the kernel itself.
- samus 3y agoThey could, but their users really won't like that. They have their workflows that they got used to. In practice it's gonna be GNU Coreutils and Glibc and the other usual suspects. If they bundle something more exotic, it better be for a very good reason. For example musl on Alpine or what Android does.
- Fnoord 3y agoOpenBSD uses BSD_Auth instead of PAM. So you cannot use your YubiKey with doas via PAM on the Linux ports. At least not in the same way, as they do not support caching it seems.
- xorcist 3y ago> without breaking everything Except all exiting use of sudo ... It's such an entrenched tool that I'm sure there a compatible replacement could be useful. Personally I would appreciate someone to take on the mess that is PAM. It was much too complex from the start and it hasn't become better over the years.
- PrimeMcFly 3y agoOpenBSD is mainly used by hobbyists and not sysadmins, which is why there are not complaints about the missing functionality.
- kristjank 3y agoOpenBSD is mainly used where other Unices can be used, and provides widely used software like OpenSSH, OpenBGPD and OpenSMTPD. To say that it's a hobby project strikes me as very ignorant. That said, it is not very easy to convince the developers that a function is missing because it's a pretty opinionated project, and they might not share the user's definition of needed functionality. Thankfully, they're nowhere near ebassi levels of functionality deletion disorder.
- PrimeMcFly 3y ago> OpenBSD is mainly used where other Unices can be used, That's a pretty general statement, and I'd say to that not really. It's very much a hobbyist OS. A few people use it at home as firewalls, a few small businesses maybe, but it's mostly hobbyists and developers. > To say that it's a hobby project strikes me as very ignorant. I mean, I've been familiar with the project for over 20 years, so I don't think I'm ignorant at all. The developers primarily make the OS for themselves and people with the same ideas and priorities. > That said, it is not very easy to convince the developers that a function is missing because it's a pretty opinionated project, and they might not share the user's definition of needed functionality. Right, the devs prioritize their own needs, and can do so because it's a hobbyist OS.
- deleted 3y ago[deleted]
- speed_spread 3y agoPriorities. If a fundamental security tool's design limits it's trustworthiness, it greatly reduces it's usefulness and "breaking" it's interface is thus warranted.