LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 12-23-2023, 05:18 AM   #16
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,927

Rep: Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320

Quote:
Originally Posted by Alfred-Augustus View Post
Yeah, I would like a very locked-down Linux that don't require password. Lets say I am building a Linux laptop for my parents (who is computer illiterate). Would be great if they don't have to mess with passwords, but still surf the web safely.

Just like my mom bought an iPad from Apple Store and just started using it. No passwords needed.
what you missed, you don't need root access, just start a browser as a regular user, even without password. That is possible, more or less like on android (or ios).
But in such cases you need to protect your root account. Also you can switch on automatic updates (like on smartphones).
 
Old 12-23-2023, 06:54 AM   #17
henca
Member
 
Registered: Aug 2007
Location: Linköping, Sweden
Distribution: Slackware
Posts: 978

Rep: Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667
Quote:
Originally Posted by Slax-Dude View Post
Use a live-distro (get one here: https://download.liveslak.org/slackware64-15.0-live/ and modify it to auto-login.
Use it on a separate network from all your other devices.
Turn it off when you are done "surfing the internet".

Nothing is absolutely safe.
The most you can do is to make it the least unsafe possible.

Please note that a passwordless computer is more unsafe than one with a password...
Yes, this is absolutely the best solution for users not suitable or capable of maintaining their OS installation. With a live CD/DVD/BluRay on a read-only media in a computer without any other internal storage no one will be able to permanently tamper with any files.

Even for someone who only needs the computer to "surf the web" maintenance of the system is mandatory. Slackware 15.0 was released Feb 2 2022, less than two years ago. Since then there have been no less than 31 security updates for Mozilla Firefox in Slackware 15.0 at the time of this writing, the last update only a few days ago:

Code:
+--------------------------+
Tue Dec 19 21:24:05 UTC 2023
...
patches/packages/mozilla-firefox-115.6.0esr-x86_64-1_slack15.0.txz:  Upgraded.
  This update contains security fixes and improvements.
  For more information, see:
    https://www.mozilla.org/en-US/firefox/115.6.0/releasenotes/
    https://www.mozilla.org/security/advisories/mfsa2023-54/
    https://www.cve.org/CVERecord?id=CVE-2023-6856
    https://www.cve.org/CVERecord?id=CVE-2023-6865
    https://www.cve.org/CVERecord?id=CVE-2023-6857
    https://www.cve.org/CVERecord?id=CVE-2023-6858
    https://www.cve.org/CVERecord?id=CVE-2023-6859
    https://www.cve.org/CVERecord?id=CVE-2023-6860
    https://www.cve.org/CVERecord?id=CVE-2023-6867
    https://www.cve.org/CVERecord?id=CVE-2023-6861
    https://www.cve.org/CVERecord?id=CVE-2023-6862
    https://www.cve.org/CVERecord?id=CVE-2023-6863
    https://www.cve.org/CVERecord?id=CVE-2023-6864
  (* Security fix *)
It does require some responsibility to let someone out on the internet. The responsibility is not only about protecting them and their data, but also about protecting the rest of internet from them. Most serious Internet Service Providers will take some responsibility and block users which maliciously or unknowingly is spreading spam or malware.

However, if you are willing and capable to do at least weekly maintenance and support of their system the auto-login feature of SDDM or other login managers might be useful.

regards Henrik
 
1 members found this post helpful.
Old 12-23-2023, 10:18 PM   #18
Alfred-Augustus
Member
 
Registered: May 2022
Posts: 91

Original Poster
Rep: Reputation: 7
Quote:
Originally Posted by pan64 View Post
what you missed, you don't need root access, just start a browser as a regular user, even without password. That is possible, more or less like on android (or ios).
But in such cases you need to protect your root account. Also you can switch on automatic updates (like on smartphones).
Ok. So, I uninstalled sudo. Now the user does not have root access.

Last edited by Alfred-Augustus; 12-23-2023 at 10:20 PM.
 
Old 12-24-2023, 02:38 AM   #19
dchmelik
Senior Member
 
Registered: Nov 2008
Location: USA
Distribution: Slackware, FreeBSD, Illumos, NetBSD, DragonflyBSD, Plan9, Inferno, OpenBSD, FreeDOS, HURD
Posts: 1,068

Rep: Reputation: 147Reputation: 147
Thumbs down Apple harmfulness

Quote:
Originally Posted by rizitis View Post
[...]Apple's control over the operating system ensures a consistent and secure user experience. [...]
False propaganda! Apple even colludes with government/police to abuse/monitor users, such as when there were protests in a certain area/country, Apple turned off people's cameras, and does other things to harm people's security! This is why why Free/Libre/Opensource Software (FLS, OSS, FOSS, FLOSS) is superior to harmful proprietary software, which also tends to inconsistently change interfaces with no way to get old features back.

Last edited by dchmelik; 12-24-2023 at 02:43 AM.
 
Old 12-24-2023, 03:03 AM   #20
henca
Member
 
Registered: Aug 2007
Location: Linköping, Sweden
Distribution: Slackware
Posts: 978

Rep: Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667
Quote:
Originally Posted by Alfred-Augustus View Post
Ok. So, I uninstalled sudo. Now the user does not have root access.
Are you running Slackware? By default the sudo settings in Slackware does not allow any normal user root access.

regards Henrik
 
1 members found this post helpful.
Old 12-24-2023, 03:05 AM   #21
Alfred-Augustus
Member
 
Registered: May 2022
Posts: 91

Original Poster
Rep: Reputation: 7
Quote:
Originally Posted by dchmelik View Post
False propaganda! Apple even colludes with government/police to abuse/monitor users, such as when there were protests in a certain area/country, Apple turned off people's cameras, and does other things to harm people's security! This is why why Free/Libre/Opensource Software (FLS, OSS, FOSS, FLOSS) is superior to harmful proprietary software, which also tends to inconsistently change interfaces with no way to get old features back.
How do you know your executable is acutally built from Opensource code? And not have something like a backdoor added in.

Last edited by Alfred-Augustus; 12-24-2023 at 03:11 AM.
 
Old 12-24-2023, 04:15 AM   #22
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,927

Rep: Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320Reputation: 7320
Quote:
Originally Posted by Alfred-Augustus View Post
How do you know your executable is acutally built from Opensource code? And not have something like a backdoor added in.
That is a different question, in general you need to know the source of that executable (not the source code, but where it was downloaded from). The content of official package repositories are documented, so you can check them.
 
Old 12-24-2023, 04:41 AM   #23
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,363

Rep: Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335
I think it's best to proceed on the basis that disabling the login or enabling sudo for root on a machine others have access to will never be safe. The experience of raising youngsters will teach you that!Offer any motivation and they'll figure it out fast.
 
Old 12-24-2023, 04:52 AM   #24
rufwoof
Member
 
Registered: Nov 2017
Distribution: Kernel+busybox+ssh+vnc+alsa (framebuffer)
Posts: 201

Rep: Reputation: Disabled
Quote:
Originally Posted by lostintime View Post
Hi Alfred-Augustus,

To autologin when booting to console (runlevel 3), edit /etc/inittab. Something like this:

c1:12345:respawn:/sbin/agetty --autologin <username> --noclear 38400 tty1 linux
--noclear 38400 tty1 linux

Consult the respective display manager docs to autologin when booting to runlevel 4 with a display/login manager. With sddm that comes packaged with Slackware, edit /etc/sddm.conf:

Code:
[Autologin]
User=<username>
There is no requirement to directly edit /etc/sddm.conf. Autologin can be configured with the KDE System Settings tool, Startup and Shutdown --> Login Screen (SDDM) --> Behavior button.

Most display/login managers support autologin and password-less logins. Some display/login managers are designed not to support root logins. Logging in as root with sddm is supported.

Surfing the web without credentials is straightforward because most web browsers support storing credentials. Similarly, email clients support storing credentials too.

I hope that helps. Have fun!
The default (internal one used if no other /etc/inittab exists) in busybox
https://elixir.bootlin.com/busybox/l...amples/inittab just uses askfirst and straight to /bin/sh that might be another alternative to using getty

Unlike others who suggest "don't do that" IMO if you just use the laptop/whatever for general browsing (no banking etc.) then I don't see any harm in treating it as a 'open' device (no password). If its stolen then unless there's a strong password and encryption the thief could see whatever was on the device anyway.

I more often run as root on a passwordless bootup. As am I happy to telnet into BBS's that any in-middle 'attacker' could see/modify. Doesn't tend to happen, more of just a bother rather than a critical issue if it did.

Any dark hat of any esteem is hardly likely to spend the time/effort targeting a individual, are more inclined to go after bigger fish (servers).

But yes, when it comes to banking or other sensitive data then you should have a separate system/method for that. I boot a pristine freshly pre-configured setup for that, where no changes are saved and its just used to go direct to my banks web site, nowhere else before or after.

Much of security is the identification and fixing of security issues that 'COULD' happen, and directing towards everything (all data) being secure, even stuff you or nobody else cares about. Whilst in the background there's google whose recording everything about you, totally in the open - and many simply don't care about that. Consider for instance that you're about to go to some-site.com and you enter that into your browser that requests the IP associated with that from a 8.8.8.8 dns server i.e. google controlled. So google knows where you're headed and can pull in the unencrypted front page of that web site. They may even get to see your encrypted data flow of that - which yields what type/method of encryption might have yielded that encrypted data sequence from that unencrypted sequence. Alongside a million other tricks/measures that they make.
 
Old 12-24-2023, 07:12 AM   #25
Alfred-Augustus
Member
 
Registered: May 2022
Posts: 91

Original Poster
Rep: Reputation: 7
Quote:
Originally Posted by henca View Post
Are you running Slackware? By default the sudo settings in Slackware does not allow any normal user root access.

regards Henrik
Yes, I am Slackware. I enabled sudo per Youtube.
 
Old 12-24-2023, 01:50 PM   #26
rizitis
Member
 
Registered: Mar 2009
Location: Greece,Crete
Distribution: Slackware64-current, Slint
Posts: 663

Rep: Reputation: 496Reputation: 496Reputation: 496Reputation: 496Reputation: 496
Quote:
Originally Posted by dchmelik View Post
False propaganda! Apple even colludes with government/police to abuse/monitor users, such as when there were protests in a certain area/country, Apple turned off people's cameras, and does other things to harm people's security! This is why why Free/Libre/Opensource Software (FLS, OSS, FOSS, FLOSS) is superior to harmful proprietary software, which also tends to inconsistently change interfaces with no way to get old features back.
My intention was not and is not to make propaganda in favor of Apple.I just explained how the iPad works and why it can work like that.I say clearly that Root is Apple and not the user.

Merry Christmas
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Are wireless keyboard safe to use? linuzfreak Linux - Hardware 6 05-11-2014 08:30 PM
Not login in mysql safe mode telltobalaji Linux - General 2 07-04-2012 10:15 PM
Mouse and keyboard lockup in Safe mode with Networking Newbie - linux Linux - Newbie 2 11-17-2011 05:11 PM
midi keyboard, how to make sound?midi keyboard, how to produce sounds? Blyiss Linux - Software 10 03-24-2007 08:53 PM
safe guarding your system by not allowing anyone to login as root abhis_mail2002 Fedora 6 05-14-2006 02:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 12:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration