logoalt Hacker News

leothetechguytoday at 5:25 PM2 repliesview on HN

Wow. This never crossed my mind but of course that's so simple. There really needs to be a better solution.


Replies

lrvicktoday at 5:29 PM

There is. Simply do not install sudo and do not allow access to root at runtime. I am serious. There is absolutely nothing you cannot run unprivileged these days. Can even run sshd from a systemd user unit in your home folder, and even assign port 22 to it if needed with Linux Capabilities.

show 3 replies
dist-epochtoday at 9:29 PM

on Windows the UAC (GUI sudo equivalent) requires actual user input (keyboard, mouse) on a dialog presented in a secure way (can't be faked by malware)

show 1 reply