Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178349

Re: Security hole in LXDE?

From <tomas@tuxteam.de>
Newsgroups linux.debian.user
Subject Re: Security hole in LXDE?
Date 2017-03-02 21:40 +0100
Message-ID <tgFG2-7vm-9@gated-at.bofh.it> (permalink)
References (1 earlier) <tgwt5-13g-23@gated-at.bofh.it> <tgxfs-1z0-11@gated-at.bofh.it> <tgxS9-29S-1@gated-at.bofh.it> <tgyOd-2Mh-1@gated-at.bofh.it> <tgzAB-3lq-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, Mar 02, 2017 at 08:01:38AM -0600, David Wright wrote:

[...]

> If you're trying to clarify things, you have to tighten that up
> considerably. Any regular user can start synaptics without a password,
> as I already posted in this thread.

Yes. I was explicitly excluding DE authentication foo (like PolicyKit
and similar) -- first to explore the simpler sudo path and second,
because I'm definitely the wrong person to give advice related to
desktop environments. I know very little about them and... I don't
like them, to be honest.

> I can guess what you mean, and I don't think that is what happened.
> (What I _think_ you mean is that by using the root password in that
> situation on one occasion, the system has "remembered", and now you
> don't need the apssword any more. I don't think that happened. I think
> the OP configured something at an ealier time and has forgotten.)

I don't think either, and given Hans' last answer, it seems he has a
pretty standard sudo configuration, his user belonging to sudoers.
I don't remember whether that is Debian default or if you've to do
something explicitly to achieve that. I'd guess it's the latter, but
hey.

> I think I would lose the ability to configure wifi APs as a user
> if I lost sudo.

Perhaps. I don't know what PolicyKit is able to do -- the whole dance
around DBus would suggest that they want to have some communication
accross privilege domains, so it seems to be geared to that, but what
do I know.

> But I can't see that there's any point in removing sudo if you
> . add noone to group sudo
> . add nothing to /etc/sudoers.d/
> . add nothing to /etc/sudoers
> 
> Would I be right?

Yes. I described removing the package sudo as the more drastic
variant, only when you want to avoid at all costs that a user be
added to the sudo group (or, more precisely: this would then have
no effect).

> BTW one thing I don't understand about sudo is why
> /etc/sudoers.d/README is not world-readable.

Funny. README, but you can't :-)

Seems a fairly harmless mistake, perhaps a too literal interpretation
of "/etc/sudoers and all files under /etc/sudoers.d are sensitive".

Better than the other way around, though.

Regards
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAli4gUgACgkQBcgs9XrR2kZw+ACcC+b5ll9T+W8cEYKbg2Eud9LD
WoYAn3W69gajGVIMO+Va5LbFZ3aT2wJ/
=ne0W
-----END PGP SIGNATURE-----

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 10:30 +0100
  Re: Security hole in LXDE? Jonathan Dowland <jmtd@debian.org> - 2017-02-27 11:00 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:20 +0100
      Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 16:40 +0100
      Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 11:50 +0100
        Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 12:40 +0100
          Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 13:20 +0100
            Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 14:20 +0100
              Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 14:40 +0100
                Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:20 +0100
              Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-03-02 15:10 +0100
                Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:40 +0100
      [SOLVED] Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-06 18:30 +0100
        Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 19:40 +0100
          Re: [SOLVED] Re: Security hole in LXDE? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-03-06 19:50 +0100
            Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 20:00 +0100
              Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 20:40 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 21:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Curt <curty@free.fr> - 2017-03-06 21:50 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 22:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 22:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-07 13:10 +0100
            Re: [SOLVED] Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-06 20:50 +0100
  Re: Security hole in LXDE? Davor Balder <davor@cropakglobal.com> - 2017-02-27 11:10 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:30 +0100
      Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 12:20 +0100
        Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-27 23:00 +0100
          Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-28 11:10 +0100
            Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
          Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-28 13:40 +0100
            Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
              Re: Security hole in LXDE? Lisi Reisz <lisi.reisz@gmail.com> - 2017-03-01 01:00 +0100
    Re: Security hole in LXDE? cbannister@slingshot.co.nz - 2017-03-25 07:20 +0100
  Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:10 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 12:30 +0100
      Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:50 +0100
      Re: Security hole in LXDE? Pontus Goffe <goffe.pontus@gmail.com> - 2017-02-27 15:50 +0100

csiph-web