Egregoros

Signal feed

fedops ๐Ÿ’™๐Ÿ’›

@fedops@fosstodon.org

#childfree, #foss #zfs, #privacy, #selfhosting, #hiking, #gardening, #nature #conservancy, #EV #physicalmedia. Unix and Linux sysadmin turned industrial OT security architect. Forest smallholder.

Please fill in your bio before following.

"When you talk, you are only repeating what you already know. But if you listen, you may learn something new." - The Dalai Lama

Avatar: alt.sysadmin.recovery coat of arms by Joe Creighton.

Posts

Latest notes

@phnt I'd argue the *average* non-techie user would be better off using the computer like a phone. They don't know how to protect themselves, so somebody else needs to do it - like application devs, as you say.

But of course these people don't need access to suid binaries in the first place. It is just a convenience feature to be able to do potentially dangerous admin tasks from a regular account. Convenience and security don't mix.
@kirby @rl_dane

@phnt I think Android is a valid counterpoint.

The problem is though that everybody is preconditioned to turn SElinux off the moment they run into an issue (usually about 3 minutes after installing a distro) and then leave it at that.

Security comes through a multi-layer approach. If you turn off all but one layer (in these recent cases sudo.conf) things go pear-shaped if this single layer breaks. That's just bad.

@kirby @rl_dane