4 ms·
I agree, it always feels strange putting my root password into a box that just popped up. True, it's only ever been in direct connection with a command line pro
by milliams 3y ago
I agree, it always feels strange putting my root password into a box that just popped up. True, it's only ever been in direct connection with a command line program I'm running, but there's nothing hard linking the terminal with the GUI window.
I think that either the terminal program should print something like a PIN which is repeated in the window to cross-check, or the window should be able to use some restricted window manager feature (like Windows' fullscreen greying out thing) to prove that it's not just a random Qt/GTK window from an attacker's script.
- Cu3PO42 3y agoThe problem is that in a sense it is just some random Qt/Gtk window. I have recently written my own PolKit agent. It runs purely in userspace without any special privileges. An attacker could kill your legitimate PolKit agent, register itself as your agent, even act as one, and also steal your password the next time you do actually authenticate something. In that sense a PIN linking the command line to the agent window doesn't save you. I agree this situation needs improving, the problem just runs much, much deeper. On the other hand: if an attacker placed a modified sudo that steals your password in ~/.local/bin, it would also be Game Over. Much of the current security model breaks as soon as the attacker has code execution. EDIT: I'd also like to highlight this: > or the window should be able to use some restricted window manager feature (like Windows' fullscreen greying out thing) to prove Your Wayland compositor also runs in userspace. Even if it is supposed to check that some calls come from euid 0, an attacker may be able to circumvent them if the attacker runs in the same context as the compositor. Again, the security problem runs very deep.
- kaba0 3y agoAs much as I love linux, it is very painful to accept the state of “security”, this is beyond criminal. Especially that many people just put their head into the sand. The age-old xkcd about linux being secure only about your video card driver is still true to this age, with no clear sign of improvement. Also, frankly I don’t understand why there is no more cross-pollination between android and linux userspace - the former has actually solved this issue properly. I’m afraid the answer is that “it is not written in c”.
- tredre3 3y ago> I’m afraid the answer is that “it is not written in c”. I don't think it has anything to do with it. Android's security comes from design, not language. Each application runs under its own UID and not all applications can draw arbitrary content on your screen, for example. Those things could be on the Linux Desktop. And maybe flatpak will bring it to us. But for now I can already hear the screeching about "freedom" and "the Unix philosophy".
- hulitu 3y ago> Android's security comes from design "This application requires storage permission. Grant ?" Yes. Comes from design. /s
- KETHERCORTEX 3y agoStill better than Flatpak's "install time permissions".
- DEADMINCE 3y ago> the window should be able to use some restricted window manager feature (like Windows' fullscreen greying out thing) No FOSS desktop is even close to offering this. The windows 'greying out thing' is an entirely separate desktop instance, for example. A lot of security consideration was put into designing it. I don't think any FOSS desktop is working on anything even remotely similar, which is a shame.
- vbezhenar 3y agoWhat prevents any random Windows application to make a screenshot and apply "greying out" filter to it? I mean, I launch a game and it puts full-screen image of whatever it wants. It doesn't take any special permissions to make a screenshot either. The only true security feature I remember was implemented in Windows many years ago. After you got security prompt, you would need to press Ctrl+Alt+Delete and type password there. Supposedly only Windows itself could handle that combination.
- DEADMINCE 3y ago> What prevents any random Windows application to make a screenshot and apply "greying out" filter to it? I mean, I launch a game and it puts full-screen image of whatever it wants. It doesn't take any special permissions to make a screenshot either. Because you would be able to alt+tab to other tasks, and that application would be able to still execute code as it was able to before. It's not any kind of security 'behind the scenes'. > The only true security feature I remember was implemented in Windows many years ago. Or perhaps you didn't realize all the engineering that was taking place behind just what you see. This[0] blog post gives a good overview of some of the security architecture that went into making that elevation prompt. Honestly, MS has been leading the pack in OS security for some time. They are leagues ahead of MacOS and Linux. [0] https://learn.microsoft.com/en-us/archive/blogs/uac/user-account-control-prompts-on-the-secure-desktop https://learn.microsoft.com/en-us/archive/blogs/uac/user-acc...
- vbezhenar 3y agoWhy would I do "alt-tab"? Do you think users typically type alt-tab when asked for admin permissions? I never did that. It's all security theater.