I was initially skeptical but the superior simplicity and rigor won me over.
protip: nixos lets you use doas instead of (or in addition to) sudo. Since i run obsd serverside and nixos on the edge, this works great for me
programs.doas.enable = true;
protip: nixos lets you use doas instead of (or in addition to) sudo. Since i run obsd serverside and nixos on the edge, this works great for me
programs.doas.enable = true;
Many sudo policies are often kind of horrible (even by default) and often facilitate privilege escalation, and then there was CVE-2019-14287 ( < 1.8.28 ) and CVE-2021-3156 ( < 1.9.5p2 ) which were plenty nasty. It's just way too huge for a setuid program, security tools shouldn't represent security holes as best as we can get away with it.
[1] https://www.thehacker.recipes/infra/privilege-escalation/uni...
security = {
doas.enable = true;
sudo.enable = false;
};
environment.systemPackages = [ pkgs.doas-sudo-shim ];