Might be a good move
Might be a good move
Posted Jun 27, 2025 23:08 UTC (Fri) by linuxrocks123 (subscriber, #34648)In reply to: Might be a good move by mjg59
Parent article: GNOME deepens systemd dependencies
> running everything in parallel provides no indication to the user what they should be trying and is going to be confusing if the face recognition fails because they're looking down at their keyboard to find the fingerprint reader.
As long as they find the fingerprint reader, they won't have a problem. pam_any is successful if *ANY* of the authentication options succeeds.
> The complexity that exists isn't gratuitous, it solves real problems for real people.
Agree to disagree.
> But I *need* software that solves these problems because I have users and policies that have these requirements
Not users, I wouldn't think, but, I am sure you have *policies* with those requirements, likely the same *policies* that gave CrowdStrike's customers so many problems a year ago (and serves them right, I'd say).
> telling me that this software shouldn't exist doesn't make my problems go away.
A problem doesn't exist because software that meets stupid requirements doesn't exist. A problem exists because someone has stupid requirements in the first place. Now, if you can't solve the "someone has stupid requirements" problem, then sure, maybe you do need to use or create software that meets the stupid requirements as a workaround.
But can't you at least cordon the stupid software off from the rest of the system and not make it the default? Must you really expand the attack surface of the login prompt so much that you then have to take heroic measures to give each individual login prompt its own UID to protect it from *other instances of itself*?
I'd say no. I'd say let the enterprise buffoons write their own greeter and maintain it themselves. But, I'm on Slackware, so none of this is my problem anyway.
