Back

I just need to write this somewhere. I have no clue why nobody is talking
about that, but multiuser systems are conceptually wrong. There should only
be one user on your *personal* computer. Security shouldn't be tied to that
at all.

And even if we assume this is somehow normal, it still doesn't fix any
security problems. A while back, I was doing something very illegal:
helping my friends install VPNs. Most of them have software related jobs
and Linux is their main operating system, so naturally I recomended for
them some random chinese xray gui client. An interesting fact about it: It
tries to hijack DNS requests and create a TUN as the default route (which
is normal thing for vpns). To do this, it runs pkexec or something to
prompt the user for a root password. Twice. Do you know how many "Is it
normal that this random application asks my password, twice?" questions
I got? - **None**! It's already become normal for random applications
to prompt for a root password, even when they shouldn't (or shouldn't do it
more than one time).

It is so stupid, even conceptually! For some reason, we try to limit what
applications can do by treating them like users with different access
levels, I guess? As if multiple people use your PC. Some of them are you,
they don't have any power to change or modify anything, and some are more
like an owner (imagine if you owned your PC, crazy thoughts... /sarcasm),
who can do whatever they want. But at night, when no one's watching, you
change your closes and become a superhero - root!... It so stupid it hurts
my brain. Why do you need that costume play? Why can't I just say "this app
can't do rm -rf /, but can change my DNS and network settings"?

(insert xkcd 1200 here)

For someone like me, if you want to experiment with a single-user
environment, delete your `/etc/passwd` and `/etc/shadow` files (**don't
forget to change your init system to login automatically!**), compile your
kernel with `CONFIG_MULTIUSER=n` and embrace simplicity!

My experimentation showed that only docker and the openssh server had a
hard requirement for multiuser setup. To replace openssh, you can use
bearssh, that has a build option to work in single-user environments.