-
Notifications
You must be signed in to change notification settings - Fork 2
Description
sudo has this timestamp_timeout option that doesn't re-prompt you for a password within, say, 5 minutes of entering a password
It seems that please doesn't have this option yet, but also I'd like to propose another modification that could make this option even better — slightly less convenient, but more secure — by using the concept of PINs, so instead of not re-prompting you for the full password during this timestamp_timeout period, the please command should instead prompt you every time, but not for your full password, but for a secondary, shorter password (aka "PIN")
This way you don't have to risk some wrong copy&paste or something worse doing anything as root within the blessed period
I understand that with proper more granular permissions this might not be as important, but at the same time not everyone will bother with granularity #1, so this is still useful and and improvement over the total passwordlessness!