Re: Why does sudo return success for bad password?
Grant Taylor via sudo-users <[email protected]> Sat, 21 Mar 2020 01:16:19 -0600
| Newsgroups | gmane.comp.tools.sudo.user |
|---|---|
| Organization | TNet Consulting |
| Message-ID | <[email protected]> |
On 3/21/20 1:07 AM, Jeffrey Walton wrote: > Thanks Grant. You're welcome. > Re: the information leak. Probably not. When a bad password is entered > the attempt is throttled by the OS. The information leak is already > present through timing. So there is no increase in risk for sudo. I consider that to be an OS (distro?) bug. Remember, sudo wants to not be the source of the information leak. It can't help it if the OS (distro) leaks the information. -- Grant. . . . unix || die ____________________________________________________________ sudo-users mailing list <[email protected]> For list information, options, or to unsubscribe, visit: https://www.sudo.ws/mailman/listinfo/sudo-users