4 ms·
> Sudo is security theater. Yes indeed. > Malware can make a fake unprivileged sudo that sniffs your password. Not on my Linux workstation though. No sudo co
by TacticalCoder 5mo ago
> Sudo is security theater.
Yes indeed.
> Malware can make a fake unprivileged sudo that sniffs your password.
Not on my Linux workstation though. No sudo command installed. Not a single setuid binary. Not even su. So basically only root can use su and nobody else.
Only way to log in at root is either by going to tty2 (but then the root password is 30 characters long, on purpose, to be sure I don't ever enter it, so login from tty2 ain't really an option) or by login in from another computer, using a Yubikey (no password login allowed). That other computer is on a dedicated LAN (a physical LAN, not a VLAN) that exists only for the purpose of allowing root to ssh in (yes, I do allow root to SSH in: but only with using U2F/Yubikey... I have to as it's the only real way to log in as root).
It is what it is and this being HN people are going to bitch that it's bad, insecure, inconvenient (people typically love convenience at the expense of security), etc. but I've been using basically that setup since years. When I need to really be root (which is really not often), I use a tiny laptop on my desk that serves as a poor admin's console (but over SSH and only with a Yubikey, so it'd be quite a feat to attack that).
Funnily enough last time I logged in as root (from the laptop) was to implement the workaround to blacklist all the modules for copy.fail/dirtyfrag.
That laptop doesn't even have any Wifi driver installed. No graphical interface. It's minimal. It's got a SSH client, a firewall (and so does the workstation) and that's basically it. As it's on a separate physical LAN, no other machine can see it on the network.
I did set that up just because I could. Turns out it's fully usable so I kept using it.
Now of course I've got servers, VMs, containers, etc. at home too (and on dedicated servers): that's another topic. But on my main workstation a sudo replacement function won't trick me.
- jcgrillo 5mo agoThanks for sharing this, that seems like a very cool setup. I have a very old good-for-almost-nothing laptop that would be perfect for this, might just have to copy you!
- lrvick 5mo agoIn my case I use QubesOS so sudo is useless even if present since every security domain is isolated by hypervisor. For servers, sudo or a package manager etc should not exist. There is no good reason for servers to run any processes as root or have any way to reach root. Servers should generally be immutable appliances.
- bee_rider 5mo agoThis thread was kicked off by somebody who said: > Realistically if you have installed malware, you need to do a full wipe of your computer anyway You might be the exception to this sentiment. But out of curiosity, after all that setup would you feel confident trying to recover from malware (rather than taking the “nuke it from orbit” approach?).
- TacticalCoder 5mo ago> But out of curiosity, after all that setup would you feel confident trying to recover from malware (rather than taking the “nuke it from orbit” approach?). Oh no, I'd still nuke everything from orbit should I find anything indicating a local exploit succeeded. But the thing is: if on one system a local exploit has less probability to give root, then the probability that on that same system I'd know I need to nuke everything from orbit would be higher than on a system where root is easier to obtain. I was however answering to the part about subverting sudo: and I both agree (it's totally trivial to abuse sudo) and disagree ("everybody uses sudo") with the part about sudo.
- bee_rider 5mo agoI agree. My surreptitious goal was to emphasize to anyone reading along: this person has put in the extra effort, but even they will not try to recover a compromised system. It is just too risky.
- nozzlegear 5mo agoFYI, in English the phrase "since years" is grammatically incorrect and sounds unnatural to a native speaker's ears. The correct phrase would be "I've been using that setup for years." /aside
- sufficientsoup 5mo agoYeah, a "seit Jahren" flashed through my mind as I read it.
- kaonwarb 5mo agoI've heard this often enough from English speakers from India that I think it is accepted grammar in that region.
- lemoncucumber 5mo agoTo my ears it “since years” sounds like it’s missing an “ago” after it (or like the GP said “for years” sounds even more natural). It makes me think of another similar one: I've noticed that British English speakers will say e.g. "the new iPhone will be available from September 20th" To my ears that sounds like it's missing an “onwards” after it (or “starting September 20th” would sound even more natural).
- regularfry 5mo agoIs the meaning different? I'm struggling to see how "from September 20th" would have a different implication to "starting from September 20th" (or similar) given the context.
- lemoncucumber 5mo agoThe meaning is the same, it just sounds weird to my ears in the same way that “since years” does (Also I just noticed the extra “it” in my previous comment, oops).
- TacticalCoder 5mo ago
- aiscoming 5mo agotell us about your disk encryption setup. and do you use secureboot?
- WesolyKubeczek 5mo agoWhen you update your packages, are you using that ssh laptop?
- GoblinSlayer 5mo agoWhy disallow password login when you have 30 char password?
- TacticalCoder 5mo ago> Why disallow password login when you have 30 char password? I only disallow password login over SSH. It's still technically possible to log in at a virtual console (like tty1 / tty2 / etc.) using a password (btw only root has a 30 characters password). Usually you do not allow to directly log in as root by SSH: but in my case it's basically the way I want it done. So I allow root to log in by using SSH but only with a Yubikey.
- walletdrainer 5mo ago>but then the root password is 30 characters long, on purpose, to be sure I don't ever enter it, so login from tty2 ain't really an option My phone password is that long, we’re still only talking about taking a few seconds to enter it when sober. Most people will quickly develop the necessary muscle memory in regular use.
- nine_k 5mo agoAre root logins only allowed from that particular LAN? Because ssh localhost is a thing. I would say that the inability to obtain a session with elevated privileges from a normal session is key. The problem with sudo is that it gives the same shell some superpowers, so it's exploitable. Even ssh might be impenetrable, if not for the /dev/<pid>/fd of the ssh invocation, and even that can only read.