5 ms·
On the contrary, giving Gimp/Krita/VLC root access to my computer makes no sense to me. Do people think that distribution developers are hand combing through a
by jcastro 2y ago
On the contrary, giving Gimp/Krita/VLC root access to my computer makes no sense to me.
Do people think that distribution developers are hand combing through all those apps? Untrusted by default is more scalable.
- cassianoleal 2y ago> giving Gimp/Krita/VLC root access to my computer Why would you give those apps root access?
- NewJazz 2y agoLocal privilege escalation.
- cassianoleal 2y agoAs in, sudo? Again, why?
- NewJazz 2y agoAccidental, not purposeful. As in, any unrestricted process with user privileges on Linux can up to root through vulnerabilities in the kernel or other components. Namespaces, LSMs, and seccomp limit that exposure.
- cassianoleal 2y ago> giving Gimp/Krita/VLC root access to my computer > unrestricted process with user privileges on Linux can up to root through vulnerabilities in the kernel or other components Getting pwnd via vulnerabilities is very different from giving root access. You're arguing with a strawman, I'd rather not engage.
- deleted 2y ago[deleted]
- NewJazz 2y agoI'm not arguing. Just informing.
- weikju 2y agonevermind root. The apps have unrestricted access to your filesystem under the same privileges as your user -- in other words, they have access to all your personal files and configurations and keys. Who needs root?
- PlutoIsAPlanet 2y ago> nevermind root. The apps have unrestricted access to your filesystem under the same privileges as your user Easy to get root anyway, just add an alias to sudo to .bashrc and whenever the user follows an online instruction guide into fixing something they'll get root privileges. or overwrite LD_PRELOAD for the user or replace the users desktop files and pretend to be another application (because you can overwrite /usr/share/applications launchers in .local/share/applications)
- cassianoleal 2y agoWouldn't those attacks all require the user to have set up passwordless sudo?
- verall 2y agoYou can change sudo into an alias that steals your sudo password and then does whatever else. Not that it makes a huge difference in practice, IMO. The apps most users run (i.e. distro apps) are plenty trusty for normal threat models. Apps that run real untrusted code (web browser) have their own sandboxes. And people with more serious threat models can run qubes or tails or whatever
- NewJazz 2y agoQubes is great.
- cassianoleal 2y agoThis is a fair point but orthogonal to the one I was responding to. In any case, a lot of Flatpak's sandbox can be overridden at build time. The sandbox will protect the user against bugs but not as much against a malicious developer.
- PlutoIsAPlanet 2y ago> Why would you give those apps root access? You shouldn't but you install debs/rpms from the internet which get root permissions during install.
- cassianoleal 2y agoNot the apps though. The packaging system yes, but whatever scripts run as part of the installation of a package is the package maintainer's responsibility. Not trusting your distro's package maintainers means you don't trust anything on your computer.