Can we please stop talking about that sudo bug? It only affects systems using an insane configuration (allow $command as anyone *but* root). I can't come up with any situation where that configuration makes any sense (vs e.g. "allow $command as any member of a given group).
-
Show this thread
-
Replying to @marcan42 @yourcompanionAI
I think the reason so many people are talking about it is that it's just weird. Sure, the security implications aren't that bad, but it's just a really weird bug.
1 reply 0 retweets 6 likes -
Replying to @samvdkris @marcan42
the original source that pimped it up said it was "a security bug where anyone could get root with sudo" and didnt clarify the config until they had shown you an ad or two
1 reply 1 retweet 10 likes -
Replying to @yourcompanionAI @marcan42
Fuckin hell... Is infosec clickbait really becoming a thing now? Like no shit, if you configure it like this privesc is going to be a trivial task
1 reply 0 retweets 2 likes -
Replying to @samvdkris @marcan42
HackersNews (note the plural) has *always* been shoddily researched clickbait
0 replies 0 retweets 4 likes -
This Tweet is unavailable.
-
In an era of misinformation and clickbait, it is as much out responsibility to report factually correct information as it is to report clearly *understandable* information. A huge number of people who read your headline got "sudo is broken and anyone can become root" out of it.
1 reply 0 retweets 1 like -
Replying to @marcan42 @unix_root and
The fact is the vulnerability has such a negligible impact on real configurations that *any* reporting at all that doesn't start with a disclaimer that you're probably not affected is irresponsible.
1 reply 0 retweets 1 like -
Replying to @marcan42 @unix_root and
You started with a clickbait headline that *anyone* (myself included) would think relates to a much bigger flaw affecting common configs, followed with "Attention Linux users!", and didn't mention that the impact is small until the last paragraph of the article. That's shitty.
2 replies 0 retweets 1 like
It is not reasonable to expect every reader to carefully parse every last sentence of the article to fully comprehend what is going on. Your job as a reporter is to make information *easily comprehensible* and transmit the right level of concern. You failed at it.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.