3 ms·
> if your model is that linux is just about single-user desktops, this local exploit isn't too bad. For example, if you have passwordless sudo, you've already
by CGamesPlay 5mo ago
> if your model is that linux is just about single-user desktops, this local exploit isn't too bad.
For example, if you have passwordless sudo, you've already got a widely known LPE vulnerability lurking on your system.
- oviet 5mo agohmm have i missed anything?
- dwedge 5mo agoOnly for your user, and it means a keylogger on the system if it gets rooted can't pull your password to try on other machines. Personally I always either login as root or use passwordless sudo.
- XorNot 5mo agoYubikeys are also surprisingly annoying when setup for the as well. A working developer just needs sudo a lot. Realistically a "sudo button" would be handy, on the keyboard, with a display to show a confirmation pin for the request (probably also needs a deny button so you can try and identify weird ones).
- parliament32 5mo agoSounds like a good use case for that new Copilot button you see on newer keyboards.
- IshKebab 5mo agoYou don't even need a button. Just a secure dialog like Windows has.
- Pay08 5mo agoI mean, that's what you have pinentry for.