Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can see creating a system with zero setuid files, but I don't think this reduces PAM use, does it?


Not setuid generically, but `sudo` itself has a bunch of pam support/dependency.


I would expect sudo to also touch pam a lot, but AIUI systemd also uses pam through polkit for its ~native permission system - https://serverfault.com/questions/841306/authentication-is-r...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: