← Back to context

Comment by gruez

10 years ago

How's that any different compared to Linux? AFAIK apt packages can run arbitrary scripts as root.

There's a world of difference, as long as you are using only default repositories (which you should). Apt itself is root, of course, but it is (or should be) trustworthy. All other apps never see root access unless they need it - and if it is needed, then the package maintainer has checked the package to make sure it only uses root when necessary. Kind of like Apple checking apps on AppStore.

No respectable package would put up a fake sudo prompt only to stash away your password for later use.

  • It's a good thing Dropbox isn't doing that, then.

    • Then please explain how it manages to set the accessibility privilege at every login after the user explicitly revokes it. I can see only two options:

      1) the Dropbox client stores the password and uses it to hack the accesses db at every login.

      2) the Dropbox client runs as root and does the same thing.

      Both options are simply terrible from a security point of view

      2 replies →

Linux packages come from the distribution and are controlled by the distribution, not some random 3rd party business.