Hacker News
new
past
comments
ask
show
jobs
points
by
exyi
4 hours ago
|
comments
by
fragmede
4 hours ago
|
[-]
Could link it to a yubikey via pam.d so you need a fingerpress to authenticate.
reply
by
pastage
3 hours ago
|
parent
|
next
[-]
Physical attestations are hard to solve, I think it would be nice if all TPMs in laptops had this. Then the problem becomes how do you automate stuff that needs to be done.
reply
by
lrvick
3 hours ago
|
parent
|
prev
|
[-]
And then the moment you authenticate, the fake sudo still executes its payload.
Yubikeys do not fix this issue.
reply