gksudo potentially very insecure

Rouslan Solomakhin solomarv at clarkson.edu
Tue Jul 5 07:30:06 CDT 2005


On Tue, 2005-07-05 at 13:19 +0200, Wouter Stomp wrote:
> A solution would be to not ask for the password again in gnome when
> starting the same program again, but do ask for it when starting a
> different program. I don't think that will pose a burden to anyone. At
> the commandline, with sudo, the current behaviour is no problem, and I
> think that is what you are referring to when saying it would be a
> burden to type it over and over again.

IMHO, the best solution would be to pop up a notification window (i.e.,
information dialog) when gksudo is not going to ask for a password. One
extra click is not as hard as entering the whole password, but it will
make users aware of their increased privileges.

Cheers,
Rouslan Solomakhin





More information about the ubuntu-devel mailing list