TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Richard Stallman, su, and the 'wheel' group (2004)

56 点作者 wannacboatmovie11 个月前

11 条评论

tgma11 个月前
I think it is worthwhile to understand and steelman Stallman [lolz]:<p>Stallman is not anti-security and is indeed pro-privacy[1], i.e. you should be able to deploy security systems to keep your data secure from adversaries. However, a security system should be deployed to protect the user from adversaries, not protect admins from the users and give admins power over the user. It&#x27;s the power asymmetry that is used to oppress the users that bugs him. (In fact, time and time again, the actual security of the system is a joke, as was in his particular story, but nevertheless the boogeyman is there and is set up by the admins to restrict the users.)<p>Note that we are talking about a different era and deployment of computer systems. I have seen firsthand university systems that are effectively run by students as peers for the most part, but some power-hungry clueless hired admin inevitably comes up and wants to deploy spyware and overprotective policies on the students.<p>[1]: another example of this is Secure Boot. He has no problem with Secure Boot in principle as long as the keys are under the control of the user, not the manufacturer.
评论 #40765848 未加载
评论 #40766211 未加载
评论 #40765845 未加载
评论 #40771632 未加载
评论 #40766458 未加载
zer00eyz11 个月前
Ahhh Stallman!<p>Stallman is open sources resident lunatic. And for better or worse he&#x27;s ours and we should embrace him. Not because we think what he says is right, rather for his purity of vision and conviction. You don&#x27;t have to agree with him, but you have to respect how far he&#x27;s willing to go to make a point.<p>And this: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=Pube5Aynsls" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=Pube5Aynsls</a>
评论 #40765683 未加载
评论 #40765879 未加载
评论 #40765736 未加载
评论 #40765870 未加载
评论 #40765713 未加载
helb11 个月前
Related: &quot;Why GNU su does not support the `wheel&#x27; group (2002)&quot;, <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=37175754">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=37175754</a>, 143 comments
asimovfan11 个月前
As i was reading the the quote by stallman i became somewhat introspective and i thought for a while and the then the shallowness of the last sentence of the blog post itself was like a cup of water thrown in my face.
kelnos11 个月前
I suppose RMS&#x27;s came up in a very different time when it came to computing, and pre-modern-internet computing had much less an emphasis on security, but his takes on things like this always seem so bizarre to me.
评论 #40765838 未加载
mesrik11 个月前
By far most nuisance for me has been that Linux distros that ship with wheel GID different than it&#x27;s <i>BSD side 0 (zero). Debian hasn&#x27;t been shipping with wheel group by default, but Red Hat and many its descendants it&#x27;s GID 10.<p>The macOS and BSD&#x27;s don&#x27;t ship with root group, Linuxen either doesn&#x27;t ship with wheel group or it&#x27;s GID mismatch what&#x27;s on BSD side.<p>The difference will cause issues and system tools misbehaving. Bit different if NAS is </i>BSD based and using NFSv4 or newer, since user and group mapping is based names and not any more ID values they were earlier. But NFS GID mapping does not work properly whichever NFS is used, it&#x27;s just different kind of misbehaving.<p>This can be fixed linux (debian etc, missing), add &quot;wheel:x:0:&quot; line &#x2F;etc&#x2F;group, right after root group. And with Red Hat based changing that GID 10 to 0.<p>Of course then &#x2F;etc&#x2F;idmap.conf the usual &quot; [Mapping]<p>Nobody-User = nobody Nobody-Group = nogroup<p>[Translation] Method = nsswitch &quot;<p>Is worth checking also.<p>The rationale adding secondary GID 0 &quot;wheel&quot; after first original root GID 0 is that, if you check how std <i>nix tools work, when those look up by name they will use GID what&#x27;s set there, and when they look up by GID they quit looking after they find matching first value that was found.<p>Therefore above solution works both ways, and your NFS shares from </i>BSD&#x27;s always shows correct value and correct group name that matches the value. I think I&#x27;ve learned this workaround about 30 years back now.
评论 #40797141 未加载
1vuio0pswjnm711 个月前
&quot;Stallman is definitely not someone I&#x27;d want in charge of the security of my system.&quot;<p>That is Stallman&#x27;s point. Some users do not want to place someone else, maybe a so-called &quot;tech&quot; company, in charge of the security of the user&#x27;s system.
userbinator11 个月前
Isn&#x27;t the existence of GNU su itself an inconsistency? It seems like RMS&#x27; vision was an environment in which everyone is effectively root, and su wouldn&#x27;t be necessary.
评论 #40765882 未加载
kasabali11 个月前
&gt; Stallman is definitely not someone I’d want in charge of the security of my system.<p>..but you&#x27;d be ok Microsoft being in charge of signing kernel images for secure boot, right?
perbu11 个月前
It is hard to imagine a more opinionated system than GNU.
评论 #40765630 未加载
评论 #40765924 未加载
hestefisk11 个月前
I always thought wheel was a BSD thing?
评论 #40765722 未加载