"Gnome Disks" grants regular users full access to hard disks without a password prompt

Hi there,

I installed gnome-disk-utility from Pamac.
The weird situation is that application allows the regular user to do pretty much all the destructive operations on the hard disks without a single password prompt.

Shouldn’t those operations such as disk partitioning and formatting be password protected as happens in GParted, for example?

How could I password protect any disk operation tried by this application with a password prompt like in GParted?

Thank you

@pfspace
I guess you can try to set your Firewall at a higher level or you can go into

Settings--->Users&Groups

https://wiki.archlinux.org/title/Group

https://unix.stackexchange.com/questions/6689/prevent-non-root-user-from-formatting-a-partition

According to the link below, system drives always require a password. At least that was the case when this was reported in 2021.

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987671

thanks for reporting this but it is not a dangerous bug because the disk 
wiping in your case on the USB stick could have been done anyway without 
password while for system drives this always requires a password.
1 Like

Usually, when a software can do superuser actions without explicitly asking for privileges, it uses Polkit.

Thank you all for your help.

MLXQt’s solution given by the links provided, kinda solved the problem but not for long.

After editing the file udisks2.policy regular users could not write to the devices. That was what I wanted. But after a second attempt, reloading the application, they could.

I think I’m better getting rid of gnome-disks to avoid “accidents” anyway.

Thank you very much for your help and support.

NOTHING to do with the OP’s questions.

@jrichard326 yes when using Disk ANY formatting, changing of mount points, and other feature of Disk should ALWAYS ask for ones password. In Manjaro it does not ask. Personally getting rid of Disk isn’t the answer. The answer in this case is just to double check what you want done before applying the settings.