social.tchncs.de is one of the many independent Mastodon servers you can use to participate in the fediverse.
A friendly server from Germany – which tends to attract techy people, but welcomes everybody. This is one of the oldest Mastodon instances.

Administered by:

Server stats:

3.7K
active users

#polkit

0 posts0 participants0 posts today
Replied in thread

@Lycoris

I want to try #OpenSuSE #Tumbleweed again. My only turn-off from it was that zypper is a little slow as a cli package manager goes (not a huge deal), and that they didn't have #PolKit enabled by default, so setting up things like your printer required using the root password, which is brain dead.

I really hope they have that last one fixed, because it's just arguably the wrong approach, and should be treated as a bug.

Rooted another OSCP machine this morning. There is no other exploit that has been more widespread and easy to leverage than pwnkit (CVE-2021-4034). I've simply lost count of the the number of machines I've been able to use this on to get root access from a low-privilege account. For people who do this kind of stuff, this post is a cold take, but I just wanted to come here and state the obvious. #OSCP #pwnkit #polkit #CVE-2021-4034 #Linux #pkexec #setuid

From the Ubuntu website: "A local privilege escalation vulnerability was found on polkit’s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn’t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it’ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine."

One thing that I think we've lost over the last 20 years is "audio cues" #linux #foss #kde #gnome #opensource -- the desktop used to give a lot more audio feedback as to the events & status of events.

Empty the recycle bin? It had s simple audio cue play

Copy a folder? You have a audio cue to communicate success.

New email? Cue AOL charming & cringy "You've got mail.wav"

OS Startup? You feel like you are getting excited to get something done withe Windows XP - 7 and early 2000s Ubuntu startup sounds.

I think this principle could be taken so much farther -- perform a #rsync Why not have a audio cue for both Success.ogg and Failure.ogg -- or what about #polkit password verification, you are multi tasking on the phone or doing something in your office -- having a cue to redirect your attention to that you need to enter a password would be helpful.

Same thing goes for #pacman #yay and #paru in #archlinux

There are times you are compiling a program and it needs extra privileges to install but you don't notice it -- it would make a huge difference if we had a hook system and could Enable/Disable audio cues & notifications -- that would be a huge improvement.

I could really see this also bringing a lot of value in #linuxphone space, with #ubuntutouch #postmarketos #sxmo and others.

Its really hard to know what your missing when its been so long since you had it.

Plug in a USB Flash Drive? Audio Cue

Connect / Disconnect your phone to your computer? Audio Cue

Remote SSH Connection logs into your machine? Notification & Audio Cue.

With the right sound packs there is so much room for improvement -- #steamdeck #steamos v3 does a good job with this too giving subtle cues as you navigate the UX, startup, shutdown, etc...