Fuckin hell... Is infosec clickbait really becoming a thing now? Like no shit, if you configure it like this privesc is going to be a trivial task
-
-
Replying to @samvdkris @marcan42
HackersNews (note the plural) has *always* been shoddily researched clickbait
0 replies 0 retweets 4 likes -
This Tweet is unavailable.
-
Sure, it may not be factually wrong, but the title is very misleading. And nowhere in the article do you explain how small the actual security implications really are.
0 replies 0 retweets 0 likes -
This Tweet is unavailable.
-
The article is *more* confusing than the original vuln report, which clearly stated the vulnerable config. By dressing it up in all that superfluous info, you dilute the message of the limited impact. More info is appreciated *only* when you take care to keep the message clear.
0 replies 0 retweets 1 like -
This Tweet is unavailable.
-
It only affects configurations that restrict access as root *but allow access as -1*, i.e. use ALL. The way you phrase it it sounds like it affects any config that allows access as a user or group that isn't root.
2 replies 0 retweets 0 likes -
Do you expect journalists to tell about ALL in the same line, expecting that everyone would immediately understand what we are taking about? If you carefully read the article, it has also been written for people who don't know what's Sudo, what's sudoers and ALL parameters.
1 reply 0 retweets 0 likes -
This Tweet is unavailable.
Dude, all I'm saying is you should have started the article with "While the chances that you are affected are small, you should read on if you use an unusual sudoers configuration."
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.