Can we please stop talking about that sudo bug? It only affects systems using an insane configuration (allow $command as anyone *but* root). I can't come up with any situation where that configuration makes any sense (vs e.g. "allow $command as any member of a given group).
-
Show this thread
-
Replying to @marcan42 @yourcompanionAI
I think the reason so many people are talking about it is that it's just weird. Sure, the security implications aren't that bad, but it's just a really weird bug.
1 reply 0 retweets 6 likes -
Replying to @samvdkris @marcan42
the original source that pimped it up said it was "a security bug where anyone could get root with sudo" and didnt clarify the config until they had shown you an ad or two
1 reply 1 retweet 10 likes -
Replying to @yourcompanionAI @marcan42
Fuckin hell... Is infosec clickbait really becoming a thing now? Like no shit, if you configure it like this privesc is going to be a trivial task
1 reply 0 retweets 2 likes -
Replying to @samvdkris @marcan42
HackersNews (note the plural) has *always* been shoddily researched clickbait
0 replies 0 retweets 4 likes -
This Tweet is unavailable.
-
Sure, it may not be factually wrong, but the title is very misleading. And nowhere in the article do you explain how small the actual security implications really are.
0 replies 0 retweets 0 likes -
This Tweet is unavailable.
The article is *more* confusing than the original vuln report, which clearly stated the vulnerable config. By dressing it up in all that superfluous info, you dilute the message of the limited impact. More info is appreciated *only* when you take care to keep the message clear.
-
-
This Tweet is unavailable.
-
It only affects configurations that restrict access as root *but allow access as -1*, i.e. use ALL. The way you phrase it it sounds like it affects any config that allows access as a user or group that isn't root.
2 replies 0 retweets 0 likes - Show replies
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.