Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #210087 > unrolled thread
| Started by | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| First post | 2019-06-19 06:30 +0200 |
| Last post | 2019-07-02 14:50 +0200 |
| Articles | 20 on this page of 61 — 24 participants |
Back to article view | Back to linux.debian.user
Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-19 06:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? john doe <johndoe65534@mail.com> - 2019-06-19 08:00 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-19 08:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl <carlf@panix.com> - 2019-06-19 13:40 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 07:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Richard Hector <richard@walnut.gen.nz> - 2019-06-20 07:40 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 09:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-20 11:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? rhkramer@gmail.com - 2019-06-20 14:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl <carlf@panix.com> - 2019-06-20 13:00 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 14:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-20 18:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl Fink <carlf@panix.com> - 2019-06-21 21:50 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-22 01:00 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 04:30 +0200
Re: Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-22 10:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? rhkramer@gmail.com - 2019-06-22 12:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 17:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Brad Rogers <brad@fineby.me.uk> - 2019-06-22 18:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 18:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-22 18:50 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-22 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 16:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl <carlf@panix.com> - 2019-06-22 14:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 02:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-22 10:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-22 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-22 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 11:50 +0200
Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-22 12:30 +0200
Re: Off topic: remaja (teens) <tomas@tuxteam.de> - 2019-06-22 12:40 +0200
Off-topic: Action [Was: Re: Off topic: remaja (teens) Erik Christiansen <dvalin@internode.on.net> - 2019-06-22 13:40 +0200
Re: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-22 23:40 +0200
Off topic: Carbon. Was: Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-23 01:10 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-23 01:50 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Elmo <moelmoel2714@gmail.com> - 2019-06-23 03:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-23 09:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Elmo <moelmoel2714@gmail.com> - 2019-06-23 10:00 +0200
Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-23 10:50 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-23 16:00 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) rhkramer@gmail.com - 2019-06-23 18:00 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Curt <curty@free.fr> - 2019-06-23 18:30 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-23 19:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) <tomas@tuxteam.de> - 2019-06-23 11:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Joe <joe@jretrading.com> - 2019-06-23 12:30 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Georgios <gpdsbe@mailbox.org> - 2019-06-23 20:10 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Joe <joe@jretrading.com> - 2019-06-23 22:50 +0200
Re: Off topic: Carbon. John Hasler <jhasler@newsguy.com> - 2019-06-23 23:10 +0200
Teenagers (was: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?) rhkramer@gmail.com - 2019-06-22 12:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 16:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Jimmy Johnson <field.engineer@gmail.com> - 2019-06-23 01:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Andy Smith <andy@strugglers.net> - 2019-06-23 02:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-23 11:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Richard Hector <richard@walnut.gen.nz> - 2019-06-24 02:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Andy Smith <andy@strugglers.net> - 2019-06-24 02:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-25 06:00 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? mick crane <mick.crane@gmail.com> - 2019-06-25 09:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Aidan Gauland <aidalgol@fastmail.net> - 2019-06-25 10:00 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-25 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-25 14:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? andreimpopescu@gmail.com - 2019-07-02 14:50 +0200
Page 1 of 4 [1] 2 3 4 Next page →
| From | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| Date | 2019-06-19 06:30 +0200 |
| Subject | Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yaAop-5zf-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Hello all Debian Users, Consider the hypothetical scenario below. I often encountered cases on systems in television stations when they configured sudoers like this snippet below: %remaja ALL=(ALL:ALL) ALL The rationale for above is most programs on such systems can only be accessed by users which are member of remaja (teens) group via sudo, so their sysadmins giving remaja user group full administrator privileges. Is it dangerous? Regards, Bagas
[toc] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2019-06-19 08:00 +0200 |
| Message-ID | <yaBNw-6iY-3@gated-at.bofh.it> |
| In reply to | #210087 |
On 6/19/2019 6:06 AM, Bagas Sanjaya wrote: > Hello all Debian Users, > > Consider the hypothetical scenario below. > > I often encountered cases on systems in television stations when they > configured sudoers like this snippet below: > > %remaja ALL=(ALL:ALL) ALL > > The rationale for above is most programs on such systems can only be > accessed by users which are member of remaja (teens) group via sudo, so > their sysadmins giving remaja user group full administrator privileges. > Is it dangerous? > We can't answer to this, the pros and cons are to be weighed. -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-06-19 08:10 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yaBXb-6Bl-1@gated-at.bofh.it> |
| In reply to | #210087 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Jun 19, 2019 at 11:06:59AM +0700, Bagas Sanjaya wrote: > Hello all Debian Users, > > Consider the hypothetical scenario below. > > I often encountered cases on systems in television stations when > they configured sudoers like this snippet below: > > %remaja ALL=(ALL:ALL) ALL > > The rationale for above is most programs on such systems can only be > accessed by users which are member of remaja (teens) group via sudo, > so their sysadmins giving remaja user group full administrator > privileges. Is it dangerous? Yes, but danger's what makes life fun, after all :-) The most important part would be to explain to the group's members what this means. As a close second, frequent backups. Of course, if it's an otherwise vital system extra care would needed (a backup system or similar). There's no reason why teens shouldn't be good sysadmins, and you gotta start learning at some point. It's definitely a Good Thing they don't grow up as "just" passive smartphone consumers! Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Carl <carlf@panix.com> |
|---|---|
| Date | 2019-06-19 13:40 +0200 |
| Message-ID | <yaH6y-17a-5@gated-at.bofh.it> |
| In reply to | #210087 |
On 6/19/19 12:06 AM, Bagas Sanjaya wrote: > > Hello all Debian Users, > > Consider the hypothetical scenario below. > > I often encountered cases on systems in television stations when they > configured sudoers like this snippet below: > > %remaja ALL=(ALL:ALL) ALL > > The rationale for above is most programs on such systems can only be > accessed by users which are member of remaja (teens) group via sudo, > so their sysadmins giving remaja user group full administrator > privileges. Is it dangerous? > > Regards, Bagas > That is almost as bad as having no security restrictions at all. The correct thing to do would be to set permissions on the programs to allow them to be run by group remaja. I don't say this often. I would immediately fire the person responsible for instituting this policy on a "production" system. (It would be a good policy if the system is intended as an educational environment to allow the teens to ruin things, and learn from experience.) -- Carl Fink carl@finknetwork.com
[toc] | [prev] | [next] | [standalone]
| From | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| Date | 2019-06-20 07:20 +0200 |
| Subject | Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yaXEl-2SC-3@gated-at.bofh.it> |
| In reply to | #210095 |
[Multipart message — attachments visible in raw view] — view raw
> That is almost as bad as having no security restrictions at all. The > correct thing to do would be to set permissions on the programs to > allow them to be run by group remaja. What I thought that the correct way is to configure sudoers so that remaja group can access programs that they absolutely required via sudo (e.g. mount for mounting USB sticks). > I don't say this often. I would immediately fire the person > responsible for instituting this policy on a "production" system. (It > would be a good policy if the system is intended as an educational > environment to allow the teens to ruin things, and learn from > experience.) In fact, many television stations have most programs written for teens (age 13 and older), so sysadmins there configure sudoers which allows teens to behave like sysadmins themselves (by giving them full administrator privileges) on their production systems. Also, parental monitoring and guidance can reduce likehood of teens breaking such systems. Maybe because teens are largest marketshare for TVs.
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2019-06-20 07:40 +0200 |
| Message-ID | <yaXXH-2Z4-5@gated-at.bofh.it> |
| In reply to | #210122 |
[Multipart message — attachments visible in raw view] — view raw
On 20/06/19 4:56 PM, Bagas Sanjaya wrote: >> That is almost as bad as having no security restrictions at all. The >> correct thing to do would be to set permissions on the programs to >> allow them to be run by group remaja. > What I thought that the correct way is to configure sudoers so that > remaja group can access programs that they absolutely required via sudo > (e.g. mount for mounting USB sticks). > >> I don't say this often. I would immediately fire the person >> responsible for instituting this policy on a "production" system. (It >> would be a good policy if the system is intended as an educational >> environment to allow the teens to ruin things, and learn from >> experience.) > In fact, many television stations have most programs written for teens > (age 13 and older), so sysadmins there configure sudoers which allows > teens to behave like sysadmins themselves (by giving them full > administrator privileges) on their production systems. Also, parental > monitoring and guidance can reduce likehood of teens breaking such > systems. Maybe because teens are largest marketshare for TVs. > I think we (or at least I) must be missing some context here. For starters, this must be some specific group of teenagers. And I'm sure they're not given permission to take over running the whole TV station. Is this some specific educational environment? Or is it a TV station specifically intended to be run by and for teenagers? Something else? Richard
[toc] | [prev] | [next] | [standalone]
| From | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| Date | 2019-06-20 09:20 +0200 |
| Subject | Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yaZwt-408-3@gated-at.bofh.it> |
| In reply to | #210125 |
[Multipart message — attachments visible in raw view] — view raw
> I think we (or at least I) must be missing some context here. For > starters, this must be some specific group of teenagers. And I'm sure > they're not given permission to take over running the whole TV station. > > Is this some specific educational environment? Or is it a TV station > specifically intended to be run by and for teenagers? Something else? Richard Hector (richard@walnut.gen.nz), I am considering the case of (production) systems on TV stations for general audiences, that is TV stations that is watched by all audiences, not just teens. As long as someone is aged 13 or older, he/she is teenager. The remaja user group is for anyone that his/her age is 13 or older. My concern here is whether giving teens full administrator privileges on those production systems can be dangerous/vulnerable or not, in fact that psychologically they are very unstable.
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2019-06-20 11:10 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yb1eW-55v-23@gated-at.bofh.it> |
| In reply to | #210129 |
On 2019-06-20, Bagas Sanjaya <bagasdotme@gmail.com> wrote: > >> I think we (or at least I) must be missing some context here. For >> starters, this must be some specific group of teenagers. And I'm sure >> they're not given permission to take over running the whole TV station. >> >> Is this some specific educational environment? Or is it a TV station >> specifically intended to be run by and for teenagers? Something else? > Richard Hector (richard@walnut.gen.nz), I am considering the case of > (production) systems on TV stations for general audiences, that is TV > stations that is watched by all audiences, not just teens. As long as > someone is aged 13 or older, he/she is teenager. The remaja user group Normally the teenage category has both a lower and an upper limit, the latter being 19. > is for anyone that his/her age is 13 or older. My concern here is > whether giving teens full administrator privileges on those production > systems can be dangerous/vulnerable or not, in fact that psychologically > they are very unstable. > If you're giving your psychologically unstable remajas full administrative privileges you are effectively giving them root; sudo affords the ability to fine-tune the accorded rights in such a way as to limit the amount and nature of the havoc your adolescent sudoers may eventually raise (when and if they do go bonkers).
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2019-06-20 14:10 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yb438-6Oq-13@gated-at.bofh.it> |
| In reply to | #210129 |
On Thursday, June 20, 2019 02:57:18 AM Bagas Sanjaya wrote: > > I think we (or at least I) must be missing some context here. For > > starters, this must be some specific group of teenagers. And I'm sure > > they're not given permission to take over running the whole TV station. > > > > Is this some specific educational environment? Or is it a TV station > > specifically intended to be run by and for teenagers? Something else? > > Richard Hector (richard@walnut.gen.nz), I am considering the case of > (production) systems on TV stations for general audiences, that is TV > stations that is watched by all audiences, not just teens. As long as > someone is aged 13 or older, he/she is teenager. The remaja user group > is for anyone that his/her age is 13 or older. My concern here is > whether giving teens full administrator privileges on those production > systems can be dangerous/vulnerable or not, in fact that psychologically > they are very unstable. I guess I don't understand either, and I'd like to. I'm guessing the teens in question work for (or are interns at) the station -- they are not TV viewers on some sort of interactive TV which they can control (to some extent) from home?
[toc] | [prev] | [next] | [standalone]
| From | Carl <carlf@panix.com> |
|---|---|
| Date | 2019-06-20 13:00 +0200 |
| Message-ID | <yb2Xn-5VO-1@gated-at.bofh.it> |
| In reply to | #210122 |
On 6/20/19 12:56 AM, Bagas Sanjaya wrote: > >> That is almost as bad as having no security restrictions at all. The >> correct thing to do would be to set permissions on the programs to >> allow them to be run by group remaja. > What I thought that the correct way is to configure sudoers so that > remaja group can access programs that they absolutely required via > sudo (e.g. mount for mounting USB sticks). I would instead make the specific programs the students/teens should be using executable by them without needing sudo. Linux permissions make this very straightforward. > >> I don't say this often. I would immediately fire the person >> responsible for instituting this policy on a "production" system. (It >> would be a good policy if the system is intended as an educational >> environment to allow the teens to ruin things, and learn from >> experience.) > In fact, many television stations have most programs written for teens > (age 13 and older), so sysadmins there configure sudoers which allows > teens to behave like sysadmins themselves (by giving them full > administrator privileges) on their production systems. Also, parental > monitoring and guidance can reduce likehood of teens breaking such > systems. Maybe because teens are largest marketshare for TVs. OK, which meaning of "program" are you using here? In American (and UK) English, it can mean either "set of instructions that run on a computer" or "television entertainment item." You seem to be using it both ways in this message or confusing the two. -- Carl Fink carl@finknetwork.com
[toc] | [prev] | [next] | [standalone]
| From | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| Date | 2019-06-20 14:50 +0200 |
| Subject | Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yb4FP-71p-1@gated-at.bofh.it> |
| In reply to | #210136 |
[Multipart message — attachments visible in raw view] — view raw
Carl (carlf@panix.com) said: > OK, which meaning of "program" are you using here? In American (and > UK) English, it can mean either "set of instructions that run on a > computer" or "television entertainment item." You seem to be using it > both ways in this message or confusing the two. In this case, "program" means "instructions that run on a computer", or "software". In hypothetical scenario as I described in the starting of this thread, I imagine that TV programs run by TV stations can be thought as computer programs in TV station's production systems. > I would instead make the specific programs the students/teens should > be using executable by them without needing sudo. Linux permissions > make this very straightforward. I mean: # chown root:remaja /opt/teen-programs/bin/* && chmod 755 /opt/teen-programs/bin/* But we're considering in this thread when most age-restricted programs can only be run using sudo, that is, such programs can only be run by root or using sudo.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-20 18:40 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yb8gp-Qm-5@gated-at.bofh.it> |
| In reply to | #210140 |
On Thursday 20 June 2019 08:30:57 Bagas Sanjaya wrote: > Carl (carlf@panix.com) said: > > OK, which meaning of "program" are you using here? In American (and > > UK) English, it can mean either "set of instructions that run on a > > computer" or "television entertainment item." You seem to be using > > it both ways in this message or confusing the two. > > In this case, "program" means "instructions that run on a computer", > or "software". > > In hypothetical scenario as I described in the starting of this > thread, I imagine that TV programs run by TV stations can be thought > as computer programs in TV station's production systems. > > > I would instead make the specific programs the students/teens should > > be using executable by them without needing sudo. Linux permissions > > make this very straightforward. > > I mean: > > # chown root:remaja /opt/teen-programs/bin/* && chmod 755 > /opt/teen-programs/bin/* > > But we're considering in this thread when most age-restricted programs > can only be run using sudo, that is, such programs can only be run by > root or using sudo. As a retired Chief Engineer, one of my duties was also the holder of a letter designating me as the Chief Operator of that tv station. So one of my duties was seeing to it that the rules as published in 47 CFR that applied to both the technical operations, and the legal things were enforced. A subscription to that 47 CFR from the GPO, can be a very wise expense. Not knowing something in it is a null/void defense. Cover you ass in other words. What you want to do opens a pandora's box of stuff these teenagers might like to see aired. That means putting their stuff in a permissions sandbox that only the chief operator has rights to move the materiel out of that sandbox into the broadcast queue. IOW, someone with that letter of authority must exist, and the FCC gives him/her that veto power because he/she is also the person they'll monetarily fine at $27,000 per instance when something airs that shouldn't. And there are several categories of no-no's. Payola schemes by the General Sales Manager, backed by the General Manager himself got shut down by me. They went to the owner to get me fired, and he told them to go pound sand, I was saving lots of money. That GM got a surprise visit from the corporate bookkeeper, and was escorted out on 15 minutes notice to collect his personal stuff by a deputy for cooking the books. Anyway, what you want to do to facilitate their creativity still needs a final approval by someone with that letter giving then the power to say no. And likely an IT guy smart enough to stay ahead of their attempts to climb that fence. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Carl Fink <carlf@panix.com> |
|---|---|
| Date | 2019-06-21 21:50 +0200 |
| Message-ID | <ybxHQ-lG-7@gated-at.bofh.it> |
| In reply to | #210147 |
On 6/20/19 12:36 PM, Gene Heskett wrote: > On Thursday 20 June 2019 08:30:57 Bagas Sanjaya wrote: > >> In hypothetical scenario as I described in the starting of this >> thread, I imagine that TV programs run by TV stations can be thought >> as computer programs in TV station's production systems. >> >>> I would instead make the specific programs the students/teens should >>> be using executable by them without needing sudo. Linux permissions >>> make this very straightforward. >> I mean: >> >> # chown root:remaja /opt/teen-programs/bin/* && chmod 755 >> /opt/teen-programs/bin/* >> >> But we're considering in this thread when most age-restricted programs >> can only be run using sudo, that is, such programs can only be run by >> root or using sudo. > As a retired Chief Engineer, one of my duties was also the holder of a > letter designating me as the Chief Operator of that tv station. > So one of my duties was seeing to it that the rules as published in 47 > CFR that applied to both the technical operations, and the legal things > were enforced. A subscription to that 47 CFR from the GPO, can be a very > wise expense. Not knowing something in it is a null/void defense. > Cover you ass in other words. > > What you want to do opens a pandora's box of stuff these teenagers might > like to see aired. That means putting their stuff in a permissions > sandbox that only the chief operator has rights to move the materiel out > of that sandbox into the broadcast queue. IOW, someone with that letter > of authority must exist, and the FCC gives him/her that veto power > because he/she is also the person they'll monetarily fine at $27,000 per > instance when something airs that shouldn't. (Lots of snipping above.) You seem to be assuming that Mr. Banjaya is in the USA. While that is not impossible, given the Javanese name and non-USA usage of English, I suspect that it is not correct. -- Carl Fink carl@finknetwork.com
[toc] | [prev] | [next] | [standalone]
| From | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| Date | 2019-06-22 01:00 +0200 |
| Subject | Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybAFH-2d1-1@gated-at.bofh.it> |
| In reply to | #210208 |
[Multipart message — attachments visible in raw view] — view raw
Carl Fink wrote: > You seem to be assuming that Mr. Banjaya is in the USA. While that is > not impossible, given the Javanese name and non-USA usage of English, > I suspect that it is not correct. In Indonesia, the case resemble hypothetical case in this thread, where sysadmins in TV station doesn't care about least privilege security principle and they gave teens full root privileges, for most programs are for teens.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2019-06-22 04:30 +0200 |
| Subject | Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybDWW-4nU-3@gated-at.bofh.it> |
| In reply to | #210214 |
Bagas Sanjaya wrote: > In Indonesia, the case resemble hypothetical case in this thread, where > sysadmins in TV station doesn't care about least privilege security > principle and they gave teens full root privileges, for most programs are > for teens. What a BS! This comes from Windoz for sure. The question is contradiction in itself. As soon as you give full access to anybody, you are out of control and you loose. And yes it is dangerous. I don't see the point in the discussion. In fact if it is a teen or someone else does not make any difference.
[toc] | [prev] | [next] | [standalone]
| From | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| Date | 2019-06-22 10:40 +0200 |
| Subject | Re: Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybJIZ-7Qn-1@gated-at.bofh.it> |
| In reply to | #210218 |
[Multipart message — attachments visible in raw view] — view raw
> What a BS! This comes from Windoz for sure. I don't know. Since 2013 most programs (GUI applications) there (TV stations systems) display watermark which stated that those are for teens (optionally with parental guidance). So children have to wait until 13 in order to fully make use of those systems. > I don't see the point in the discussion. In fact if it is a teen or someone > else does not make any difference. I'm talking about (production) systems which teens are allowed to do most (administrative?) tasks with sudo, which are analogous to letting them watch TV programs designed for them, which are majority of programs offered by TV stations in real life.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2019-06-22 12:30 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybLrr-uY-1@gated-at.bofh.it> |
| In reply to | #210222 |
On Saturday, June 22, 2019 04:11:56 AM Bagas Sanjaya wrote: > I don't know. Since 2013 most programs (GUI applications) there (TV > stations systems) display watermark which stated that those are for teens > (optionally with parental guidance). So children have to wait until 13 in > order to fully make use of those systems. I still don't understand the context -- are these teens somehow working at the TV station deciding which shows to be transmitted, or are these teens at home, viewing TV, and possibly getting the option to view TV programs being broadcast with the watermark that says they must be 13 to view? > I'm talking about (production) systems which teens are allowed to do most > (administrative?) tasks with sudo, which are analogous to letting them > watch TV programs designed for them, which are majority of programs > offered by TV stations in real life. Maybe this (last) paragraph answers my question, but it is not really clear to me.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2019-06-22 17:30 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybQ7L-3iw-1@gated-at.bofh.it> |
| In reply to | #210232 |
rhkramer@gmail.com wrote: > I still don't understand the context -- are these teens somehow working at > the TV station deciding which shows to be transmitted, or are these teens > at home, viewing TV, and possibly getting the option to view TV programs > being broadcast with the watermark that says they must be 13 to view? > >> I'm talking about (production) systems which teens are allowed to do most >> (administrative?) tasks with sudo, which are analogous to letting them >> watch TV programs designed for them, which are majority of programs >> offered by TV stations in real life. > > Maybe this (last) paragraph answers my question, but it is not really > clear to me. I also have the feeling I do not know English and computers at all. What does a teen watching TV programs has to do with sudo and Linux and why would they need sudo at all? Also the word program is ambiguous in the context. Is it a TV program or a computer program? In any case - no one gives root to all to everybody or not known/skilled people - problems are to be expected.
[toc] | [prev] | [next] | [standalone]
| From | Brad Rogers <brad@fineby.me.uk> |
|---|---|
| Date | 2019-06-22 18:20 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybQU9-3NB-1@gated-at.bofh.it> |
| In reply to | #210251 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, 22 Jun 2019 17:21:14 +0200
deloptes <deloptes@gmail.com> wrote:
Hello deloptes,
>Is it a TV program or a computer program?
On TV, it's a programme.
--
Regards _
/ ) "The blindingly obvious is
/ _)rad never immediately apparent"
Well well well, you just can't tell
My Michelle - Guns 'N' Roses
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2019-06-22 18:30 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybR3P-3QJ-1@gated-at.bofh.it> |
| In reply to | #210252 |
Brad Rogers wrote: >>Is it a TV program or a computer program? > > On TV, it's a programme. > thank you
[toc] | [prev] | [next] | [standalone]
Page 1 of 4 [1] 2 3 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web