Re: Device browser, mounting, and other root tasks in KFM

"Steven D'Aprano" <[email protected]> Sun, 17 Nov 2002 23:47:38 +1100
Newsgroups gmane.comp.kde.look
Message-ID <[email protected]>
My apologies for the delay in replying to this.

On Thu,  7 Nov 2002 02:37, Henry Stanaland wrote:
> I think offering a password for move, copy, delete and other similar
> commands isn't just a good idea, but a necessary idea.  I don't want
> to have to do a bunch of stuff just to copy a wallpaper into
> /usr/share/wallpapers. If somebody wanted to be "break in" by trying
> passwords they could just try to run "kdesu."  I don't see why it
> would be a problem to offer a password box if you tried to copy an
> image to /usr/share/wallpapers.  Now, I  know fanatics would come up
> with some crap like "people are stupid and shouldn't be offered root
> access."  But if people are stupid, then we *really* need an easy way
> to do this kind of stuff.

Pardon me for a silly question, but what is wrong with just giving 
write permission to /usr/share/wallpapers to other users?

And if there is some such reason, then is there any reason why one 
can't have an alternative location ~/usr/wallpapers which is writable 
by the owner?

> But for the security conscious, I would just recommend a limit.  For
> example, don't allow more than X incorrect attempts.  After that you
> don't offer the password anymore, but just say "access denied" for
> like 5 minutes or so with some instructions on how to reset the
> clock--this is necessary as I have seen as my experience in Technical
> Support.

So lets see that I understand -- you are suggesting that since people 
are too stupid to install their own wallpapers, we should make it easy 
for them by giving them the root password anyway? Then, when they 
invariably get it wrong, we give them instructions how to bypass our 
security by resetting the timer.

That way, when Evil J. Cracker breaks into your system to install (say) 
a Britney Spears wallpaper, if he doesn't guess your root password the 
first few times, he can just reset the clock and try again.


> I have actually dreamed of this idea for over a year.  I am waiting
> till I graduate to try to code this type of stuff myself because KDE
> really sucks when it comes to handling permissions & administrative
> stuff(except in the Control Center).  I think somebody should submit
> a wish list.  This idea would be really awesome with the "remember
> password" thing. However, there are two implementations I had thought
> about.  One is, that you are in essence running "kdesu cp X X" after
> dragging a file.  The other option is to have the whole view get root
> access.  Something like the "Administrator Mode" used in the Control
> Center.  This would need some obvious graphical indications that it
> was root(perhaps a yellow bar along the side like in KMail that said
> "Full Administrative Priviledges"  or some kind of warning logo in
> the background of the window.
>
> Yes?

This makes sense. There should be some sort of equivalent to su for the 
GUI which you can enter into and out of without having to open a new 
Konq instance.


-- 
Steven D'Aprano