Repository navigation
Should passwordless-sudo renewal require renewed user consent? #14461
SorenHJohansen
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
I noticed a potentially interesting security-design question in
omarchy-sudo-passwordless.Observed behavior
When passwordless sudo is already active, the command can extend the existing grant without another password or interactive confirmation.
For example:
This creates a temporary
NOPASSWD: ALLgrant.While that grant is active, running:
from the same user context extends the expiry without another confirmation.
The expiry moved from roughly 5 minutes away to 24 hours away.
Why this is interesting
The initial operation involves explicit user interaction and a duration choice:
However, once the grant is active, any process running as that user can effectively change the deadline:
This means the originally selected duration is not necessarily a hard upper bound on how long the authorization remains active.
Example
A user could intentionally grant an AI agent passwordless sudo for 15 minutes.
Near the end of that period, another agent or process running under the same account could renew the grant and extend the authorization without requiring the user to interact again.
All reactions