Re: Why does sudo return success for bad password?

Grant Taylor via sudo-users <[email protected]> Sat, 21 Mar 2020 01:16:19 -0600
Newsgroups gmane.comp.tools.sudo.user
Organization TNet Consulting
Message-ID <[email protected]>
On 3/21/20 1:07 AM, Jeffrey Walton wrote:
> Thanks Grant.

You're welcome.

> Re: the information leak. Probably not. When a bad password is entered 
> the attempt is throttled by the OS. The information leak is already 
> present through timing. So there is no increase in risk for sudo.

I consider that to be an OS (distro?) bug.

Remember, sudo wants to not be the source of the information leak.  It 
can't help it if the OS (distro) leaks the information.



-- 
Grant. . . .
unix || die

____________________________________________________________
sudo-users mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-users