9 ms·
KDE6 release: D-Bus and Polkit Galore
- binkHN 3y agoI don't know much about openSUSE, but it's nice to see the security effort that goes on before importing a large update like KDE6.
- brnt 3y agoIt must be nice to get such a review of your code and design, and it looks like KDE appreciated it (probably they expected it, hence the early reach out). Kumbaya but non sarcastic :)
- creshal 3y ago[flagged]
- brnt 3y agoThe reviewed helped find the complexity and give pointers on how to reduce it, is the way I read it.
- genter 3y agoHow did you get your web browser to work in DOS?
- creshal 3y agoPolkit is entirely redundant (dbus has its own permission system, not that you need it) and it's trivial to build a linux desktop without it. (None of my systems have it installed, e.g.) Dbus is harder to replace, since the complexity addicts at Redhat and KDE decreed it to be The Default Linux IPC, but realistically, most programmers who think they need could do with a solution 10% as complex and 10x as fast. (dbus-broker is a step in the right direction, but not radical enough.)
- Scarbutt 3y agoWhat do you use as alternatives to xdg-desktop-portal and its backends which require rtkit/polkit?
- bandrami 3y agoI can't speak for polkit, but in the absence of rtkit the gid/uid limits set in limits.conf work just fine even over a portal. I honestly never understood what was allegedly gained by moving that logic from one place to another. (For that matter the analogy with polkit and group permissions works for a lot of things.)
- creshal 3y agoWayland and snaps/flatpaks were more overly complicated mistakes, the alternative will be to go back to drawing board and not come back until there's a solution less stupid.
- _factor 3y agoIt’s hard to sell enterprise support if your product is simple and easy to understand.
- bluGill 3y agoThe problem is everyone's 10% solution is different and so the complexity is easier than the sum total of all the others you would have.
- creshal 3y agoDBus is really quite a magical place, I'm sure if you actually dig through how open source projects use it, you'll find that the vast majority of projects don't really interact with most of its features and just do the bare minimum the protocol forces them to declare (object paths vs object class hierarchies, dbus perms vs polkit perms, ...), or they're stuff that sounded like a good idea 20 years ago and hasn't been for 15 (defining its own data serialization layer, incompatible to everything else).
- deleted 3y ago[deleted]
- lyu07282 3y agoI'm positively surprised someone is looking at all so deeply into potential desktop local privescs, I just assumed the extreme complexity of your average default plasma desktop vs. the relative few users, meant it is probably full of vulnerabilities just not worth the effort of finding them.
- surajrmal 3y agoThese sorts of articles reaffirms to me that there is a dire need to switch to capability based security models. Managing the security with the set of tools we have available in the legacy model leaves lots of room for error.
- deleted 3y ago[deleted]
- 1oooqooq 3y agothe actual end user security could get the same love. the privilege escalation dialog is mostly a windows 10 copy, but just shows: allow dbus.something.something"? the name is always meaningless and have no parameters. and there's zero way to get more information. windows at least shows the binary or PowerShell command plus the arguments.
- milliams 3y agoI agree, it always feels strange putting my root password into a box that just popped up. True, it's only ever been in direct connection with a command line program I'm running, but there's nothing hard linking the terminal with the GUI window. I think that either the terminal program should print something like a PIN which is repeated in the window to cross-check, or the window should be able to use some restricted window manager feature (like Windows' fullscreen greying out thing) to prove that it's not just a random Qt/GTK window from an attacker's script.
- Cu3PO42 3y agoThe problem is that in a sense it is just some random Qt/Gtk window. I have recently written my own PolKit agent. It runs purely in userspace without any special privileges. An attacker could kill your legitimate PolKit agent, register itself as your agent, even act as one, and also steal your password the next time you do actually authenticate something. In that sense a PIN linking the command line to the agent window doesn't save you. I agree this situation needs improving, the problem just runs much, much deeper. On the other hand: if an attacker placed a modified sudo that steals your password in ~/.local/bin, it would also be Game Over. Much of the current security model breaks as soon as the attacker has code execution. EDIT: I'd also like to highlight this: > or the window should be able to use some restricted window manager feature (like Windows' fullscreen greying out thing) to prove Your Wayland compositor also runs in userspace. Even if it is supposed to check that some calls come from euid 0, an attacker may be able to circumvent them if the attacker runs in the same context as the compositor. Again, the security problem runs very deep.
- 3y ago
- DEADMINCE 3y agoI hesitate to use the word 'bloat', but ever since DKE4 with that Avahi service or whatever it was, that's the impression I've had of KDE. It almost feels like a separate OS on top of an OS. I guess it's just not for me. About a year ago I discovered AwesomeWM and just how flexible and configurable it is - I can truly have a 100% completely customized desktop down to every detail. Even without that though I'd probably opt for something like XFCE if I wanted something with a desktop and taskbar. There's just no good reason a desktop has to be as heavy as more popular options. Even the Windows desktop isn't as heavy.
- Shared404 3y ago> Even the Windows desktop isn't as heavy. Have you used Windows recently[0]? KDE is definitely lighter than Windows, in both mental load and RAM usage. At least as of late Windows 10 and early Windows 11, which were the last times I used it with any regularity. I'll stick with sway though for now, and I'm excited for the new Cosmic version coming soon. [0] Recently is relative of course. It's been a while for me.
- deleted 3y ago[deleted]
- MSFT_Edging 3y agoI moved to i3 then to Xmonad after years of Gnome, I felt similar, just too much junk. Recently I set up a few new laptops and decided to try KDE as a "base layer" for various utilities I need, as its easier to install the DE and get the utilities as deps than download them all myself. The annoying truth about tiling WMs that I ignored for years is man it takes so much time to get set up exactly how you like it. I could drop in my xmonad setup like I've done on other machines, but I want to try one of the wayland offerings and just the time commitment is making me put it off. That being said, the most recent KDE plasma desktop is extremely snappy and polished feeling. More so than the windows desktop, and I feel like its 85% as smooth as say MacOS. I've yet to test battery life compared to a bare bones suckless tiling setup, but I'm still getting very good battery life without it.
- 3y ago
- malkia 3y agoWhy was this not done with RAII - https://invent.kde.org/frameworks/kauth/-/commit/fc70fb0161c1b9144d26389434d34dd135cd3f4a https://invent.kde.org/frameworks/kauth/-/commit/fc70fb0161c... - if there was an exception between here QVariantMap args; QDataStream s(&arguments, QIODevice::ReadOnly); s >> args; Then it won't restore the global. Also ... global ugh
- yarg 3y agoThe update doesn't seem too bad - but I did (initially) make the mistake of calling zypper from within KDE, which leads to a crash and leaves the system in an invalid state. (ctrl+alt+f4 from the login screen allows you to get to a command line without starting KDE, and that allows for the upgrade to complete.) I do think that this shouldn't be allowed; zypper should exit gracefully and inform the user how to safely perform the upgrade.