KDE6 release: D-Bus and Polkit Galore
security.opensuse.org
security.opensuse.org
the privilege escalation dialog is mostly a windows 10 copy, but just shows: allow dbus.something.something"? the name is always meaningless and have no parameters. and there's zero way to get more information. windows at least shows the binary or PowerShell command plus the arguments.
I think that either the terminal program should print something like a PIN which is repeated in the window to cross-check, or the window should be able to use some restricted window manager feature (like Windows' fullscreen greying out thing) to prove that it's not just a random Qt/GTK window from an attacker's script.
I agree this situation needs improving, the problem just runs much, much deeper.
On the other hand: if an attacker placed a modified sudo that steals your password in ~/.local/bin, it would also be Game Over. Much of the current security model breaks as soon as the attacker has code execution.
EDIT: I'd also like to highlight this:
> or the window should be able to use some restricted window manager feature (like Windows' fullscreen greying out thing) to prove
Your Wayland compositor also runs in userspace. Even if it is supposed to check that some calls come from euid 0, an attacker may be able to circumvent them if the attacker runs in the same context as the compositor. Again, the security problem runs very deep.
The age-old xkcd about linux being secure only about your video card driver is still true to this age, with no clear sign of improvement.
Also, frankly I don’t understand why there is no more cross-pollination between android and linux userspace - the former has actually solved this issue properly.
I’m afraid the answer is that “it is not written in c”.
I don't think it has anything to do with it. Android's security comes from design, not language. Each application runs under its own UID and not all applications can draw arbitrary content on your screen, for example.
Those things could be on the Linux Desktop. And maybe flatpak will bring it to us. But for now I can already hear the screeching about "freedom" and "the Unix philosophy".
"This application requires storage permission. Grant ?"
Yes. Comes from design. /s
No FOSS desktop is even close to offering this. The windows 'greying out thing' is an entirely separate desktop instance, for example. A lot of security consideration was put into designing it. I don't think any FOSS desktop is working on anything even remotely similar, which is a shame.
The only true security feature I remember was implemented in Windows many years ago. After you got security prompt, you would need to press Ctrl+Alt+Delete and type password there. Supposedly only Windows itself could handle that combination.
In contrast, on Linux, if you put a shell script in the users $PATH called 'sudo' that simply captures their password, you can (assuming the default PAM configuration) immediately use that to elevate privileges anytime you want with absolutely no intervention whatsoever. Because the password not only authenticates you, it authorizes you as well.
Because you would be able to alt+tab to other tasks, and that application would be able to still execute code as it was able to before. It's not any kind of security 'behind the scenes'.
> The only true security feature I remember was implemented in Windows many years ago.
Or perhaps you didn't realize all the engineering that was taking place behind just what you see. This[0] blog post gives a good overview of some of the security architecture that went into making that elevation prompt.
Honestly, MS has been leading the pack in OS security for some time. They are leagues ahead of MacOS and Linux.
[0] https://learn.microsoft.com/en-us/archive/blogs/uac/user-acc...
It's all security theater.
You wouldn't be able to switch to another application is the point. What you suggest greying out, would easily allow other applications to hijack that prompt or replace it with their own.
That's a large part of what 'Secure Desktop' aims to prevent, and it succeeds at doing so.
> If the policy setting is set to Prompt for credentials, malware imitating the credential prompt might be able to gather the credentials from the user. However, the malware doesn't gain elevated privilege and the system has other protections that mitigate malware from taking control of the user interface even with a harvested password.
So just knowing the credentials is not enough, they have to be used in the right context (the secure desktop).
QVariantMap args;
QDataStream s(&arguments, QIODevice::ReadOnly);
s >> args;
Then it won't restore the global. Also ... global ugh(ctrl+alt+f4 from the login screen allows you to get to a command line without starting KDE, and that allows for the upgrade to complete.)
I do think that this shouldn't be allowed; zypper should exit gracefully and inform the user how to safely perform the upgrade.
I guess it's just not for me. About a year ago I discovered AwesomeWM and just how flexible and configurable it is - I can truly have a 100% completely customized desktop down to every detail.
Even without that though I'd probably opt for something like XFCE if I wanted something with a desktop and taskbar. There's just no good reason a desktop has to be as heavy as more popular options. Even the Windows desktop isn't as heavy.
Have you used Windows recently[0]?
KDE is definitely lighter than Windows, in both mental load and RAM usage. At least as of late Windows 10 and early Windows 11, which were the last times I used it with any regularity.
I'll stick with sway though for now, and I'm excited for the new Cosmic version coming soon.
[0] Recently is relative of course. It's been a while for me.
This was the result of projects like Plasma Mobile, and also the community intentionally focusing on hardware vendors and embedded as a growth area (as now seen with deployments like the Steam Deck or Mercedes-Benz cars).
Criticism of KDE 4 as bloated is well-taken, but we've since done quite a lot to repent :-) Disclaimer: I'm a KDE contributor.
That is very interesting! I will definitely give it another look. Is it still running that service that started with 'a'? What was the reason for that? I always found that so frustrating. I remember fighting with it to try and kill it or disable it way back in the day.
> Criticism of KDE 4 as bloated is well-taken, but we've since done quite a lot to repent :-) Disclaimer: I'm a KDE contributor.
Thank you for all the work you do!
Baloo, Nepomuk's successor, has also improved a lot and file indexing can be disabled, or folders excluded from indexing.
And I agree about Plasma being lightweight: that's what I run on a 12 year old tablet which has 1GB of RAM because it has been the only touch-friendly DE that was lightweight enough for years. Now, we have Plasma mobile and Phosh that might do the job better.
Not sure why SQLite is not the default. Maybe they expect several applications to write to the DB concurrently and expect that SQLite might cause perf issues. Though there's nothing in the doc about this.
Recently I set up a few new laptops and decided to try KDE as a "base layer" for various utilities I need, as its easier to install the DE and get the utilities as deps than download them all myself.
The annoying truth about tiling WMs that I ignored for years is man it takes so much time to get set up exactly how you like it. I could drop in my xmonad setup like I've done on other machines, but I want to try one of the wayland offerings and just the time commitment is making me put it off.
That being said, the most recent KDE plasma desktop is extremely snappy and polished feeling. More so than the windows desktop, and I feel like its 85% as smooth as say MacOS. I've yet to test battery life compared to a bare bones suckless tiling setup, but I'm still getting very good battery life without it.
On my systems, it uses something like 1.2 GB of memory out of the box. Meaning you have a _very_ usable machine even with only 4 GB of RAM, as long as you can avoid the temptation to run Electron apps. Pretty sure that is impossible with Windows.
I've tried basically every Linux DE and WM since I first started using Linux in 1996, and basically haven't been happier with the overall experience than I am now. Which scares me a little bit, because every time I get comfortable with a DE, someone decides to throw it all out and rewrite the thing from scratch. (GNOME 2->3, KDE 3->4, etc.)
A fresh Windows 10 install on a system with 4GB of ram will idle at around 1GB used. Perhaps your comment is correct in regards to Windows 11, though.
KDE6 has been pretty good to me, you should try it! Or wait for 6.1.
And I'm sure you could achieve all of it somehow in awesomewm/i3wm/etc. but to me it just feels like a waste of time and a bad user experience. Perhaps I'm just getting old and rather focus on more interesting things than the configuration files of my window manager.
Disclaimer: I've been using Linux on the desktop exclusively since before Windows XP.
LOL. No. Try Window 11 then try KDE 5 or 6. No comparison.
You are comparing KDE4, a 10 year old release which was not well optimized.
KDE has become more efficient while Windows has become more bogged down and bloated with ads and telemetry and crapware. It is unusable before running a debloating script.
Windows 11 is worse than 10. Even if it was more responsive, the ads are obnoxious.
Yeah of course there are ways to get rid of all that. Plenty of decrapifier scripts on Github. I use https://atlasos.net