Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. The "Sudo flaw lets Linux users run commands as root..." article

The "Sudo flaw lets Linux users run commands as root..." article

Scheduled Pinned Locked Moved The Lounge
linuxtutorialquestion
6 Posts 5 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Offline
    B Offline
    B L Zeebub
    wrote on last edited by
    #1

    (I posted this comment on HackerNews as well): IMHO, publishing an article describing the existence of an OS or App flaw is possibly (I say that cautiously) a legitimate thing to do. But to not only describe the flaw in explicit detail, but to demonstrate how to exploit it, is irresponsible. What's next? A bunch of hackers thrashing about trying to make hay with this information before the hole is plugged in who-knows-how-many targets? I think more responsibility ought to be placed on those who disseminate this kind of information, in cases where it ends up causing harm of any kind.

    P D 2 Replies Last reply
    0
    • B B L Zeebub

      (I posted this comment on HackerNews as well): IMHO, publishing an article describing the existence of an OS or App flaw is possibly (I say that cautiously) a legitimate thing to do. But to not only describe the flaw in explicit detail, but to demonstrate how to exploit it, is irresponsible. What's next? A bunch of hackers thrashing about trying to make hay with this information before the hole is plugged in who-knows-how-many targets? I think more responsibility ought to be placed on those who disseminate this kind of information, in cases where it ends up causing harm of any kind.

      P Online
      P Online
      PIEBALDconsult
      wrote on last edited by
      #2

      Stick it in your blog or make it a comment on the article.

      1 Reply Last reply
      0
      • B B L Zeebub

        (I posted this comment on HackerNews as well): IMHO, publishing an article describing the existence of an OS or App flaw is possibly (I say that cautiously) a legitimate thing to do. But to not only describe the flaw in explicit detail, but to demonstrate how to exploit it, is irresponsible. What's next? A bunch of hackers thrashing about trying to make hay with this information before the hole is plugged in who-knows-how-many targets? I think more responsibility ought to be placed on those who disseminate this kind of information, in cases where it ends up causing harm of any kind.

        D Offline
        D Offline
        dandy72
        wrote on last edited by
        #3

        The term you're looking for is "responsible disclosure". The Linux community is always quick to rail against Microsoft for taking its sweet time to implement fixes, so given that this particular problem already has a fix, I don't think it's unfair to have these details disclosed at this point in time. Somewhat related: What I personally don't appreciate is the fact that a lot of vulnerabilities are now well-known, and I have a bunch of Android-based devices that never get any security update, so I'm very much at risk if I wanted to use any of those devices to do any sort of semi-important transaction. My newest device is on Android 6. At the time I concluded I only have myself to blame if I keep buying hardware that never gets security fixes, so I figured that was going to be my last. At some point after that, Google made some sort of vague promise that all devices would get upgrades no matter how laggard an OEM is. Has the situation changed? Should I believe that and spend a couple more hundred bucks again? I'd feel pretty stupid if I did without any assurance...

        N N 2 Replies Last reply
        0
        • D dandy72

          The term you're looking for is "responsible disclosure". The Linux community is always quick to rail against Microsoft for taking its sweet time to implement fixes, so given that this particular problem already has a fix, I don't think it's unfair to have these details disclosed at this point in time. Somewhat related: What I personally don't appreciate is the fact that a lot of vulnerabilities are now well-known, and I have a bunch of Android-based devices that never get any security update, so I'm very much at risk if I wanted to use any of those devices to do any sort of semi-important transaction. My newest device is on Android 6. At the time I concluded I only have myself to blame if I keep buying hardware that never gets security fixes, so I figured that was going to be my last. At some point after that, Google made some sort of vague promise that all devices would get upgrades no matter how laggard an OEM is. Has the situation changed? Should I believe that and spend a couple more hundred bucks again? I'd feel pretty stupid if I did without any assurance...

          N Offline
          N Offline
          Nelek
          wrote on last edited by
          #4

          :thumbsup::thumbsup:

          dandy72 wrote:

          Has the situation changed?

          No

          dandy72 wrote:

          Should I believe that and spend a couple more hundred bucks again?

          No really needed

          dandy72 wrote:

          so I'm very much at risk if I wanted to use any of those devices to do any sort of semi-important transaction

          I have never used a phone to make semi important transactions yet, and I think I will never do. I have bought a new "smartphone" not long ago, but because my old one was having hardware problems (battery dying) and to fix it would have been more expensive (apple) than what I paid for the current phone (average Samsung)

          M.D.V. ;) If something has a solution... Why do we have to worry about?. If it has no solution... For what reason do we have to worry about? Help me to understand what I'm saying, and I'll explain it better to you Rating helpful answers is nice, but saying thanks can be even nicer.

          D 1 Reply Last reply
          0
          • D dandy72

            The term you're looking for is "responsible disclosure". The Linux community is always quick to rail against Microsoft for taking its sweet time to implement fixes, so given that this particular problem already has a fix, I don't think it's unfair to have these details disclosed at this point in time. Somewhat related: What I personally don't appreciate is the fact that a lot of vulnerabilities are now well-known, and I have a bunch of Android-based devices that never get any security update, so I'm very much at risk if I wanted to use any of those devices to do any sort of semi-important transaction. My newest device is on Android 6. At the time I concluded I only have myself to blame if I keep buying hardware that never gets security fixes, so I figured that was going to be my last. At some point after that, Google made some sort of vague promise that all devices would get upgrades no matter how laggard an OEM is. Has the situation changed? Should I believe that and spend a couple more hundred bucks again? I'd feel pretty stupid if I did without any assurance...

            N Offline
            N Offline
            Nathan Minier
            wrote on last edited by
            #5

            I bought a Nokia with Android One this year; it gets actual system updates over the cellular network, which is pretty sweet. Beats the hell out of installing some OEM software on my PC and walking through an arcane update process that fails if you breathe wrong.

            "Never attribute to malice that which can be explained by stupidity." - Hanlon's Razor

            1 Reply Last reply
            0
            • N Nelek

              :thumbsup::thumbsup:

              dandy72 wrote:

              Has the situation changed?

              No

              dandy72 wrote:

              Should I believe that and spend a couple more hundred bucks again?

              No really needed

              dandy72 wrote:

              so I'm very much at risk if I wanted to use any of those devices to do any sort of semi-important transaction

              I have never used a phone to make semi important transactions yet, and I think I will never do. I have bought a new "smartphone" not long ago, but because my old one was having hardware problems (battery dying) and to fix it would have been more expensive (apple) than what I paid for the current phone (average Samsung)

              M.D.V. ;) If something has a solution... Why do we have to worry about?. If it has no solution... For what reason do we have to worry about? Help me to understand what I'm saying, and I'll explain it better to you Rating helpful answers is nice, but saying thanks can be even nicer.

              D Offline
              D Offline
              dandy72
              wrote on last edited by
              #6

              Nelek wrote:

              I have never used a phone to make semi important transactions yet, and I think I will never do.

              I'm in the same boat. People trust their phones waaaaay too much. Android devices never get fixed. Apple has now been caught sending browser queries to China. Y'know what? I'm sticking with my Windows phone. It's such a small user base, the bad buys don't bother. And yet it's still getting regular updates (despite being absolutely dead, according to the pundits)

              1 Reply Last reply
              0
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups