← Back to context

Comment by utopiah

11 hours ago

Funnily enough it wouldn't work for me as I use passwordless sudo thanks to PAM-U2F with a YubiKey Bio. I mean realistically speaking it probably would as I would just type it thinking "Hmmm weird" but still want to proceed forward ¯\_ (ツ)_/¯

Of course this style of attack would work on you. Attacker has the sudo wrapper that hooks your next yubikey tap to running any payload they want as root.

Your solution helps mitigate hardware keyloggers, which is great, but for malware in your home directory, it offers no advantages.