6 ms·
The number of times I've been stuck wondering if my keystrokes are registering properly for a sudo prompt over a high latency ssh connection. These servers I h
by written-beyond 7mo ago
The number of times I've been stuck wondering if my keystrokes are registering properly for a sudo prompt over a high latency ssh connection.
These servers I had an account setup too were, from what I observed, partially linked with the authentication mechanism used by the VPN and IAM services. Like they'd have this mandatory password reset process and sometimes sudo was set to that new password, other times it was whatever was the old one. Couple that with the high latency connection and password authentication was horrible. You would never know if you mistyped something, or the password itself was incorrect or the password you pasted went through or got double pasted.
I think this is a great addition, but only if it leads to redhat adopting it which is what they were running on their VMs.
- augusto-moura 7mo agoHad problems with faulty keyboards in the past too, never to be sure which keys were I pressed I had to type the password in a text file (much more insecure) and then paste it on the prompt. Of course this was never done in front of anyone, shoulder surfing was never an issue to begin with.
- ghighi7878 7mo agoI agree that this move is good. But you should not type sudo passwords on remote machine. Instead setup your machinr to have nopassword for special sdmin account and enable pubkey only authentication.
- written-beyond 7mo agoYeah but am I going to really open another ssh connection just to run an admin specific command. They also didn't provide an admin user, it setup with all of the extra security configurations. You couldn't even `su`
- ghighi7878 7mo agoI mean nopasswd option of sudo
- wolvoleo 7mo agoWith sudo you can also give people specific access to commands. I personally use the pam ssh agent module for this, that way you can use agent forwarding with sudo.
- ghighi7878 7mo agoI did mean nopasswd option of sudo.
- Wowfunhappy 7mo agoWhy is it better to have a nopassword admin account when using a machine remotely? The point of SSH is to resist mitm attacks, right? If someone could watch my keystrokes, I think I'd have bigger problems!
- tsimionescu 7mo agoThis resists scenarios where the machine you are running SSH from is compromised, and has a keylogger or something similar installed. SSH can't protect you from a local attacker (in fact, the SSH client binary itself could be the compromised part).
- __david__ 7mo agoYes, but if the server you’re logging into only accepts keys then leaking its password isn’t nearly as bad. Though I guess if your local ssh client is compromised then your local private keys are also compromised so you’d be screwed anyway (unless you are using a yubikey type of thing—I should get me one of those).
- Wowfunhappy 7mo agoIf I own both machines this doesn't seem entirely reasonable. (Of course a machine I own could be compromised but again, then I have other problems.)
- deleted 7mo ago[deleted]
- trvz 7mo agoReal men rawdog with root.
- znpy 7mo agoYou could have avoided the worry completely. Ssh goes over tcp that does transport control (literally the “tc” in “tcp”) and this includes retransmission in case of packet loss. If you are on a high latency ssh connection and your password does not register, you most likely mistyped it.
- written-beyond 7mo agoI am aware of that but you forgot the other conditions. Keys sometimes don't register, I'm not sure why but I do experience missing keystrokes. The passwords get updated irregularly with the org IAM so you aren't sure what the password even is. Pasting doesn't work reliably sometimes, if you're on windows you need to right click to paste in terminals, sometimes a shortcut works. Neither gives me any feedback as to what event was ever registered though.
- vman81 7mo agoYea, add a VNC jump host and a flaky spice based terminal and there are a bunch of things that can make your input not register properly.
- johnisgood 7mo agoYou can tell if you input something or not, based on the blinking cursor, in which case it is not "frozen".
- semanticc 7mo agoUnless you disable cursor blinking because you find it annoying (like I do).
- setopt 7mo agoYeah, disabling cursor blinking is the first configuration I do in any terminal.
- written-beyond 7mo agoI mean a trivial solution to all of these work around a could have been each keystroke registers a single asterisk that goes away after a delay. You wouldn't reveal the length and you'd had a standard way of informing the user that their keystroke was registered.
- layer8 7mo agoIt doesn’t tell you if backspace works, however.
- mbesto 7mo agoThe number of times i realized half way that I probably posted the wrong password and so I vigorously type the 'delete' key to reset the input is too damn high
- larsbrinkhoff 7mo agoJust type Control-U once.
- tspng 7mo agoThat's great. I've been using terminals for 20+ years, and never new about CTRL-U. Thanks! TIL.
- larsbrinkhoff 7mo agoIt's built into the Unix terminal driver. Control-U is the default, but it can be changed with e.g. "stty kill". Libraries like readline also support it.
- eptcyka 7mo agoThe Just in that sentence is wholly unjustified. There are plenty of cli/tui/console/shell shortcuts that are incredibly useful, yet they are wholly undiscoverable and do not work cross-platform, e.g. shell motions between macOS and reasonable OSes.
- QuantumNomad_ 7mo ago> shell motions between macOS and reasonable OSes All the movement commands I know work the same in the terminal on a default install of macOS as it does in the terminal on various Linux distros I use. Ctrl+A to go to beginning of line Ctrl+E to go to end of line Esc, B to jump cursor one word backwards Esc, F to jump cursor one word forward Ctrl+W to delete backwards until beginning of word And so on Both in current versions of macOS where zsh is the default shell, and in older versions of macOS where bash was the default shell. Am I misunderstanding what you are referring to by shell motions?
- ornornor 7mo agoAround 2004 someone gave me Linux CDs (I think it was mandrake?) that I tried to install. And I got stuck at the password input part of the setup, I thought it didn’t work and went back to windows. I didn’t start using Linux until 13 years later… I think I’d have switched much earlier if not for that weird UI decision.
- tankenmate 7mo agoThis decision long predates Linux. It's been a staple back to the earliest days of Unix; and it isn't a weird decision if you take into consideration of multi user systems in office environments that have non trivial security considerations (for example telecoms companies), which is exactly where Unix came from.
- wartywhoa23 7mo agoWell, if leaking the length of the password is such a big deal, why not just use a reasonably long password? Moreover, if someone can see the number of asterisks on the screen, what prevents them from seeing the actual keys that are being pressed?
- LorenDB 7mo agoOr listening to the number of keystrokes (although you can add random characters and then backspace to help mitigate this).
- tankenmate 7mo agoAgain looking back at the history of Unix, it used a 56 bit variant of DES encryption that used the user's password as the key. So only the first 8 characters of the password were used and the rest was silently unused, for example "password" and "password123" would have been the same password on early Unix. And although most BSDs and Linuxes moved in the mid 90s to PAM (and hence md5, etc) most SVR4s didn't move until late in the 90s. And at the other end, DES crypt() made its way into Unix in some v6s (~1977) and became widely available in the release of v7 Unix. So 8 character passwords were a thing for about 20 years.
- notatoad 7mo ago>a sudo prompt over a high latency ssh connection i feel this in my bones. does anybody know what level this change happens on? is this change going to affect ubuntu desktop users on any system they ssh into, or will it affect all users of a ubuntu server who have ssh'd in?
- queenkjuul 7mo agoIt's the sudo binary installed on the host -- if you're SSH'd to a 26.04 host, you'll see stars; if you're running 26.04 and SSH to a different OS, you won't (unless the remote system is also 26.04 or otherwise using rs-sudo)
- pseudohadamard 7mo agoI wonder if it'll stick though? Some years ago FreeBSD changed their setup so the initial password you set on install was echoed back to you so you could verify that the thing that'll completely lock you out of the system if you get it wrong is correctly set up. The response was total hysteria. Apparently people were setting up their 1U rack-mount servers while riding the No.8 bus and were worried other passengers were looking over their shoulders while they typed in the password. So they backed out of the change after being buried in a mountain of complaints. One thing people are really, really good at is detecting others near them, because it was essential for not getting eaten back in the day. So the chances of (a) someone wanting to shoulder-surf (b) being close enough to do so and (c) getting away with it are essentially zero. It was a security measure that made sense in 1973 when you were on a model 33 leaving a printed record in a machine room with a dozen other people, but has been completely nonsensical for several decades. Which is probably why it invokes so much irrational religious fervor.
- crazysim 7mo agoDid that echo the password back on the screen or just asterisks?
- pseudohadamard 7mo agoThe password, otherwise you have no way to check you've got it right.
- crazysim 7mo agoOh yeah, I can see why some might freak out about that.
- pseudohadamard 7mo agoMe too, in the sense that I can see why people freak out about spiders, but it's difficult to come up with any realistic scenario where you need to be worried about a random attacker standing behind you looking over your shoulder to write down your password as you install a server.
- anthk 7mo agoI mostly use Mosh for that.
- Ferret7446 7mo agoIf you have high latency wouldn't extra echoing use more bandwidth and worsen the situation? In any case, I don't understand the issue. TCP is "reliable" so it's not like you'll get dropped keystrokes. Just type the password and hit enter, and the entire string will go through when it goes through