1. I run a malware as root which modifies my image. I don't run anything as root except apt. So this is impossible.
2. Someone steals my computer and modifies the disk. Again, if they have physical access, I have already failed in my security. So this scenario is irrelevant.
Am I missing anything?
2. apt packages can run arbitrary bash scripts as root as part of their install and update process. Hopefully your third-party apt repo hygiene is good.
3. Just because you only explicitly run apt as root, does not mean no program runs as root. setuid executables exist and are unfortunately quite common in Debian.
I highly doubt it. Privilege escalation exploits are rare and fixed with utmost priority.
> apt packages can run arbitrary bash scripts as root as part of their install and update process. Hopefully your third-party apt repo hygiene is good.
Yeah, a root user should be responsible.
> Just because you only explicitly run apt as root, does not mean no program runs as root. setuid executables exist and are unfortunately quite common in Debian.
And I assume that when the root user installed those apps, he was careful and selective and did not include malware.
A statement which would be much improved with numbers. How rare? Fixed how quickly?
It's not about what you explicitly choose to run as root at the command line. That's a tiny fraction of the code that executes as root on your machine. It's about what software can do to somehow gain access to root's privilege level via exploits.
Yeah and that was a really big deal. Fixes were pushed in record time.
> It's about what software can do to somehow gain access to root's privilege level via exploits.
The correct way to deal with that is to plug exploits or write code that is less likely to be exploited. Taking away privileges from root is the exact opposite of what we should be doing.
Root access should be protected, and any bugs that break this barrier without the user's credentials should be fixed/prevented.
The root user should have absolute power to do anything. This is the basic ethos of Linux.
Taking away power from the user results in ios. I don't want Linux distros/systems to start behaving like ios.
>The root user should have absolute power to do anything. This is the basic ethos of Linux.
They're just splitting 'root' into two parts. No power has been taken away.
1. What if apt is compromised?
2. What if apt installs something which is compromised?
3. What if you run something which is compromised and escalates privilege?
Then fix it.
> 2. What if apt installs something which is compromised?
This implies apt is compromised. Goto above.
> 3. What if you run something which is compromised and escalates privilege?
If something is able to escalate privilege that's a kernel bug of the highest order and must be fixed asap.