• FizzyOrange@programming.dev
    link
    fedilink
    arrow-up
    15
    arrow-down
    1
    ·
    2 months ago

    This sounds like a great improvement. I have read the sudo source code and anyone that seriously thinks there’s no problem with it being SUID is crazy.

    That said the whole security model of sudo makes no sense. As soon as you can access a sudoers’ account you can trivially steal their password by MitMing sudo and waiting.