5 ms·
I had the "joy" of watching some guys from Perforce setup a new p4 instance. They confed /etc/sudoers so that the perforce user can run everything as root with
by panki27 2y ago
I had the "joy" of watching some guys from Perforce setup a new p4 instance.
They confed /etc/sudoers so that the perforce user can run everything as root without providing a password. I told them that this is really a bad idea, and they pulled up one of their setup guides with "enhanced security hardening".
It ended up with ~35 specific entries for binaries in sudoers, one of them being /usr/sbin/setcap - which allows you to give e.g. the Python interpreter CAP_SETUID, making a privilege escalation to root trivial again.
- dehrmann 2y agoWe love to praise Unix, but it wasn't built for modern multi-user use. FUSE was an after-thought. So were package managers, and they got added, but they require root. Users aren't sandboxed, so they can see what others are doing. These were just off the top of my head.
- fph 2y agoIs multi-user use "modern"? Back in the days everyone shared the same mainframe, now I'd say most computer systems have a single user.
- adrian_b 2y agoWhile most computers are personal computers, which have a single real human user, you still have to run a lot of untrusted programs, like the Internet browsers or whatever programs you might download from dubious sources. While perhaps the term "user" is no longer the best, there is a need even more than before to run programs with limited rights, corresponding to the rights of some pseudo-users, which should not be able to access or modify anything belonging to the real human user, unless a special permission is granted.
- calvinmorrison 2y agoSo, basically all my sandbox concerns go away if I run as root and every browser runs as its own user
- deleted 2y ago[deleted]
- Too 2y agoAndroid works like this. It's linux based and runs every app as its own user. On top of that it adds SELinux and many other isolation strategies. https://source.android.com/docs/security/app-sandbox https://source.android.com/docs/security/app-sandbox
- Dwedit 2y agoShared Web Hosting still uses multiple users.
- adrian_b 2y agoMultics had much more complex security, with access-control lists. The authors of Unix have taken most of the concepts of an hierarchical file system from Multics, the main exception being the security features, which have been replaced with the simpler owner-group-all permission bits, together with features like setuid/setgid, which may be OK for simple use cases but which is inadequate for a system with many users, where not all of them can be trusted.
- anthk 2y agoUnix 2.0 (plan9/9front) has namespaces.
- jeroenhd 2y agoUnix was very much made for multi user environments. The problem with staying compatible with Unix today is that back when Unix came to be, everyone on the system was more or less trusted. The biggest security concern was making sure that everyone who was logged in was billed correctly. On succifiently offline systems, you can still run software like that. It's quite freeing to have a server with 777 on your home directory when the biggest problem it'll cause is someone pranking you by altering your terminal color scheme to something hideous.
- noinsight 2y ago> Unix was very much made for multi user environments. ... The biggest security concern was making sure that everyone who was logged in was billed correctly. I don't know about that... It doesn't even support multiple administrators. And you can't even distinguish between actions performed by the system itself and the administrative user. Yes I know about sudo. What do you need to do and what do the (even audit) logs say about who performed an activity whenever administrative activity happens?
- timewizard 2y ago> It doesn't even support multiple administrators. You can easily create multiple accounts that have the uid 0. Groups are a fundamental part of discretionary access system and several administrative groups exist by default. Your modern desktop oriented distribution may not take advantage of these facts. > logs say about who performed an activity whenever administrative activity happens? Simply enable process accounting and setup a program to capture that information. The early BSD distributions had this and had many command line tools to query the information it stored.
- randomname93857 2y ago>> What do you need to do and what do the (even audit) logs say about who performed an activity whenever administrative activity happens? By activity you mean who run some process? doesn't enabling audit on all execve, execveat and looking at AUID besides EUID and UID fields tell you that? Or am I missing something? you may want to configure ENHANCED format in auditd for convenience.
- Vogtinator 2y agoFor multiple users on the same server it was IMO well designed. Everyone had their ~ and could place whatever libraries/binaries/etc. in there and do whatever they wanted. Package managers are way more modern than that and their design does by itself not require root (see pip). You can in fact run most package managers without root, you just won't be able to modify system files. You can use them to install a chroot as regular user, e.g. `zypper --installroot ~/tw install bash`. FUSE doesn't really relate to single vs. multi-user AFAICT. Users are perfectly sandboxed if you configure the system that way. Depending on the distribution that's even the default.
- IshKebab 2y agoOh yeah? How can I install Clang using Apt without root?
- ErikBjare 2y agoYou don't need to install it with apt
- IshKebab 2y agoIndeed but the claim was: > You can in fact run most package managers without root It is very clear from the context that dehrmann was talking about Linux distro package managers (Apt, Yum, Dnf, Apk, etc.) and as far as I know they all require root, or at least I have never once seen someone use them without root.
- ErikBjare 2y agoI figured most package managers (brew, pip, nix, npm, etc.) are not actually one of the few Linux distro package managers. You listed them almost exhaustively after all (excepting pacman).
- IshKebab 2y agoRight but as I said from the context it was clear he was talking about distro package managers, not language package managers. Nix requires root (at least by default). Brew I'll give you - I didn't know you can use it on Linux. Do people actually do that enough that it works reliably?