| ▲ | tomrod 4 hours ago |
| What? Why is sudo security theater? |
|
| ▲ | novafunc 4 hours ago | parent | next [-] |
| Any user process can append anything they want to your shell rc (.bashrc, .zshrc). In this case, they added a bash function for a fake sudo prompt. It then uses the password the user entered to run a malicious payload as root. |
| |
| ▲ | silver_sun 3 hours ago | parent [-] | | If you're running a malicious user process with write (or read) access to your files, you are arguably already compromised. | | |
| ▲ | LinXitoW 3 hours ago | parent | next [-] | | The freaking point is that basically anything worth running will have that amount of access, even Flatpaks. And you don't freaking know what's malicious before hand. | | |
| ▲ | silver_sun 3 hours ago | parent [-] | | I think that depends on your point of view. I wouldn't run a program on my computer unless I were sure that it's not malicious. And if you mean that some program I already trust could be exploited, that's true even for the Linux kernel or any sandbox / security solution you would come up with. I'm not denying that there's always a risk, but there's nothing good in running arbitrary code that you can't trust. |
| |
| ▲ | inigyou 3 hours ago | parent | prev [-] | | Exactly the point. You are already fully compromised, sudo adds no security. |
|
|
|
| ▲ | charrondev 4 hours ago | parent | prev | next [-] |
| It’s not, but the grandparent does point out 1 major flaw with sudo being a typically command that goes through normal path discovery. It makes it easier to escalate from a compromised user account to a compromised root account, since the end user is likely to type the root password into a command that can be shadowed in their user space. |
|
| ▲ | lrvick 4 hours ago | parent | prev [-] |
| Because it is trivial for unprivileged malware to phish the password and escalate to root. No production system should ever ship with sudo. |
| |
| ▲ | jorvi 3 hours ago | parent [-] | | You do realize you can do the exact same thing on macOS? Just alias sudo to whatever you want. BSD I assume you can do the same with doas. No desktop system is safe from your attack, unless you take specific precautions like chattr on the file or chmodding your home directory, but that can lead to weird breakage. | | |
| ▲ | rick_dalton 8 minutes ago | parent | next [-] | | You basically don’t use sudo on macOS though. Maybe once in a blue moon | |
| ▲ | lrvick 3 hours ago | parent | prev [-] | | No popular Linux desktop, I would grant you. I use QubesOS and my own distro, stagex. |
|
|