Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

> Also your calculator app can read your sudo password as you type it

True with X11. Fixed in Wayland.



Wayland fixed one problem, but there's no shortage of local privilege escalation bugs with which the calculator can still read the sudo password.


I want to learn more. Do you have some examples?


Just yesterday, Microsoft found a few[0]. There's no shortage of these, but more important is the haphazard way fixes are backported to longterm (e.g. [1]). This reached the point that Google's security advice is 'always follow the latest kernel'[2], except most users and distros simply cannot afford it, so they are stuck with a vulnerable system.

Linux is not unique here. In the longterm, all the typical desktop OSs will need significant structural changes far beyond 'chase vulnerabilities and patch everything all the time'.

[0] https://www.theregister.com/2022/04/27/microsoft-linux-vulne...

[1] https://nvd.nist.gov/vuln/detail/CVE-2019-15902

[2] https://security.googleblog.com/2021/08/linux-kernel-securit...


Which is still not the standard - probably will take at least a decade before we can even talk about this issue being fixed.


standard or not, it's already shipping by default in ubuntu and fedora except for when nvidia drivers are involved.

The problems will be worked out.. one way or the other.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: