Spyke

Actually Linux is far more well known than for example Windows for access denied stuff. Though bypassing it is a matter of putting sudo at the beginning of the command and putting your password in. In Windows you have to traverse through a bunch of dialogues... which isn't that hard but not as easy as the *nix approach.

2
lemmy.world

What it is actually saying is if you don't know how to gain access to edit this file you should not be editing this file.

53
f314reply
lemmy.world

When I was a kid I deleted the system32.dll file on my grandfather’s computer because it showed up in some error message. It did in fact not solve the error 😅

33
Millerreply
lemmy.world

Strictly you stopped getting that particular error message.

41
bequirtlereply
lemmy.world

I remember trying to mod a game from the xbox app, and couldn't edit even with trustedinstaller/takeown shenanigans. Turns out the files are encrypted so you can't even edit it from Linux. And if you disable encryption the game doesn't run :D

2
Appoxoreply
lemmy.dbzer0.com

Today I tried to wrestle my way with trusted installer... Went so far as to use psexec to make myself nt-authority\system and was still denied permission. ಥ_ಥ

6
Toes♀reply
ani.social

I've done that, did nt authority not work for you? It did for me on server 2008.

You might need to kill any processes with handles to it using process hacker.

1

It was a DC using 2016 Essentials...And as it's being replaced by a new server soonish, it wont matter as much anyway.
I just hope it will limp along until then.

3
lemmy.world

I wish. I spent 4 hours trying to get both I and docker to have permission to see my other drive. I finally gave up entirely and made a puid:guid that had access to everything short of root and put myself on that. It's still dubious as to whether that will work...

11

Just do it like a champ and run sudo chmod -R +777 / ! Who needs privilege access anyway?

10

Polkit asking you to type the password every few minutes when moving a bunch of files:

8
hansoloreply
lemmy.today

"You fool, I could sudo rm the whole drive right now. It's only out of my exuberant benevolence that I don't."

Later: me pressing the up key 38 times rather than type sudo apt update && upgrade

6
lemmy.today

Well, you can technically remove the immutable flag from files.. but I wouldn't

2
Appoxoreply
lemmy.dbzer0.com

Well, you can technically boot Windows into safemode or boot the install iso to modify the files owned by TrustedInstaller. But should you really do it?

1
lemmy.world

Mastering file permissions is a big part of becoming Linux capable. And it essential to the "everything is a file" ethos. Wanna lock down an important file or program? chmod is a powerful ally.

Microslop has tried to adopt a half-ass elevated permissions scheme, but with lame-ass UAC and users who've no idea why Explorer doesn't have administrator rights on their administrator account.

5
Viceversareply
lemmy.world

Windows' way is more convenient for me, than chmod:
windows allows you to regulate file access more granularly, more flexible - per any particular user , particular group.
Chmod can't do that.

2
yesmanreply
lemmy.world

Either I don't understand your comment, or you don't understand chmod. What you describe ins't beyond chmod; it's the basic functionality of chmod.

3

Via chmod you can't configure access to some arbitrary group or user. You have only the owner user, owner group and everything else is crowded into one lump "other".

4
Appoxoreply
lemmy.dbzer0.com

OP meant ACLs.
Which arent exactly straight forward in CLI in either Windows nor Linux.

4

More or less.
Until you get into nested and inherited permissions ;) Then it get's really fun.

1

chmod can do 95% of everything I've ever needed, just with the "user" and "other" category. Private files, public-readable files, public read-write files, programs I compile but anyone can run... all that is just in the "user" and "other" category of chmod.

It gets 99% if you add the sticky bit (used on /tmp) and the "group" category. Serial ports are owned by root:dialout, and mode 660. To get serial port access, just add the user to the dialout group. For group assignments in college, each partner pairing had their own group they could use. Group work files were mode 660 so groups could edit each others' work, but other groups couldn't peek.

For the last 1%, use setfacl. It does everything that explorer.exe's security tab can do.

1

setfacl can do.
It's just that some *NIX users want the stupid POSIX model and authenticating with user-ids (+ private keys) instead of proper usernames and password (and private keys).
Go figure /shrug

1
lemmy.world

So? How the hell is it supposed to know that when you're trying to do things wrong? Would you rather it let any one do anything, so long as they control the mouse?

0

Yes. Fricking yes. Do we look like we care about Windows "protecting" us? No. Nobody actually does.

1

You reached the end