Reply to post: Re: Polkit

Linux distros haunted by Polkit-geist for 12+ years: Bug grants root access to any user

dafe

Re: Polkit

Polkit is not a mitigation of user and group based capabilities.

It completely by-passes that system for the purpose of privilege escalation, and while the filters can be as fine-grained as any setuid command, Ulrike sudoers polkit's always run as root. It's a root-kit.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon