3 ms·
if your model is that linux is just about single-user desktops, this local exploit isn't too bad. or if your model is nothing but DB servers or the like. myst
by markhahn 5mo ago
if your model is that linux is just about single-user desktops, this local exploit isn't too bad. or if your model is nothing but DB servers or the like.
mystifying to me that shared, multi-user machines are not thought of. for instance, I administer a system with 27k users - people who can login. even if only 1/10,000 of them are curious/malicious/compromised, we (Canadian national research HPC systems) are at risk. yes, this is somewhat uncommon these days, when shell access is not the norm.
but consider the very common sort of shared hosting environment: they typically provide something like plesk to interface to shared machines with no particular isolation. can you (as a website owner or 0wner) convince wordpress/etc to drop and execute a script? yep.
- CGamesPlay 5mo ago> if your model is that linux is just about single-user desktops, this local exploit isn't too bad. For example, if you have passwordless sudo, you've already got a widely known LPE vulnerability lurking on your system.
- oviet 5mo agohmm have i missed anything?
- dwedge 5mo agoOnly for your user, and it means a keylogger on the system if it gets rooted can't pull your password to try on other machines. Personally I always either login as root or use passwordless sudo.
- XorNot 5mo agoYubikeys are also surprisingly annoying when setup for the as well. A working developer just needs sudo a lot. Realistically a "sudo button" would be handy, on the keyboard, with a display to show a confirmation pin for the request (probably also needs a deny button so you can try and identify weird ones).
- parliament32 5mo agoSounds like a good use case for that new Copilot button you see on newer keyboards.
- IshKebab 5mo agoYou don't even need a button. Just a secure dialog like Windows has.
- Pay08 5mo agoI mean, that's what you have pinentry for.
- AntiUSAbah 5mo agoNot to bad? So we just threat linux overall as a single user system or what?
- edelbitter 5mo agoUbuntu is not really targeting multi-user any more. Security update installation is deliberately delayed for all users, until at some point all unprivileged users ended all processes launched from the vulnerable snap image. (Firefox RPC breaks when you replace the binary, so having to reopen your browser to keep opening tabs simple because security upgrades were applied in the background would be inconvenient)