| Summary: | discover: dont ask for password all the time | ||
|---|---|---|---|
| Product: | [Applications] Discover | Reporter: | Martin Zbořil <kdebugzilla> |
| Component: | discover | Assignee: | Dan Leinir Turthra Jensen <leinir> |
| Status: | RESOLVED INTENTIONAL | ||
| Severity: | wishlist | CC: | aleixpol, nate |
| Priority: | NOR | ||
| Version First Reported In: | 5.18.5 | ||
| Target Milestone: | --- | ||
| Platform: | Kubuntu | ||
| OS: | Linux | ||
| Latest Commit: | Version Fixed/Implemented In: | ||
| Sentry Crash Report: | |||
|
Description
Martin Zbořil
2021-01-06 13:24:01 UTC
No, I'm afraid not. If Discover asked for your password once when it launched, then during the whole time the app was open, it would have full access to the entire system. That's considered a security risk today. It's far safer to have apps ask for authentication for only the minimum set of actions they need to complete the user's requests. ok, as you think, however i believe that if you ask your users to fill passwords a lot, then they will make sure to have easy/no passwords and they will type it everywhere as a reflex - just by avoiding this security risk you may be ruining security as whole. i've read your answer again and believe that you did not answered my question - i specifically mentioned sudo behaviour - not root forever, but 5 minutes of root-only operations without password prompt again - just as sudo - it runs, it ends, if you need it again you type sudo and if its within time limit and such, it does not ask for the password again.. do you think that sudo is a security risk? Those are questions for your distro, which determines the timeout duration as a part of its security policies. All Discover does is honor those settings. |