Sure, it may not be factually wrong, but the title is very misleading. And nowhere in the article do you explain how small the actual security implications really are.
Some of them even ran their own confused tests and thought it was really that bad, because sudoers is confusing and they didn't understand exactly what config they needed to have. They often accidentally gave themselves ALL outright.
-
-
(a negative control would've caught that mistake, but people rarely do negative controls when trying to quickly confirm a confusing security vuln report from the internet)
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
This Tweet is unavailable.
-
Honestly, you didn't do a great job of conveying the details. The most confusing bit is where you go straight from ALL to "in a specific scenario where you have been allowed to run a specific, or any, command as any other user except the root"
- Show replies
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.