Re: Re: su/sudo cannot X



On Wed, Jan 18, 2006 at 08:55:58PM -0500, Lei Kong wrote:
> thanks, sux works beautifully.
> but still I don't understand why sudo -s has problems,
> and on my desktop, on problem at all, and I don't remember
> doing special thing on it.
>
> As about the security concern, why is it more secure not to
> let root log into X than otherwise? why is not letting root start X
> client after su/sudo by default a good policy? I just feel it is a
> bit funny, root can do anything, it just can't open a damn window.
> Maybe I really need to dig into xauth manual for an answer.

I've been told that if a process has a window on an X server, it can
create fake events on any of the windows on the X server. This was,
ages ago, a building block for various nice user interfaces, decades
before anybody was serious about computer security. So an open root
window wound be easy prey for any stray process that managed to put
anything on your screen.

Anybody know how true this is?

-- hendrik


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • RE: Cant reboot after update
    ... Kernel panic-not syncing: VFS: unable to mount root fs on ... server in our server room just after I started a normal reboot, ... etch host running on a Dell PowerEdge 2450 server. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: X is broke... freeing multiple contexts (2)
    ... "blinkem" run as root claims unable to open sound card. ... Is "blinkem" an X application? ... In a terminal window? ... The window manager is a process separate from X. ...
    (comp.os.linux.setup)
  • Re: Another Newbie Troubles with Debian
    ... make multiple selections...for example if I wanted to install the Web Server, ... DNS Server, FTP Server along with the desktop. ... If so type 'su' followed by the root password and then run ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: server security :: user accounts, ssh, passphrases, etc.
    ... In other words, if I were to give you free access to my server, so ... that you could inspect all the system files, ... You just described root. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: K3b crashing
    ... > Try going to Packman and getting a newer version. ... thrash the disk - back to 11.7 which works as root). ... window, file list window and plus the big mauve area with the four "wizard" ... Anyway, when I start k3b as a user, the k3b screen appears with the menu bar ...
    (alt.os.linux.suse)