It’s hard to imagine something as fundamental to computing as the sudo command becoming abandonware, yet here we are: its solitary maintainer is asking for help to keep the project alive.

Archived version

  • Scrollone@feddit.it
    link
    fedilink
    arrow-up
    20
    arrow-down
    1
    ·
    17 hours ago

    To be honest, it wouldn’t take much for distro maintainers to detect that and stop it

    • JustEnoughDucks@feddit.nl
      link
      fedilink
      arrow-up
      4
      arrow-down
      1
      ·
      8 hours ago

      But who is seriously looking at the sudo code at every update. I would bet a lot of money that the vast majority simply trust him and gloss over it maximum.

      The chain of trust has to exist otherwise distrobox maintainers would spend 24 hours a day reviewing code changes and only update once every 6 months.

      • da_cow (she/her)@feddit.org
        link
        fedilink
        arrow-up
        6
        ·
        5 hours ago

        You may want to look into how the xz backdoor has been discovered. That backdoor was very well hidden. Implementing a crypto mining malware would be blatantly obvious and yes, people do in fact look at such code