It’s hard to imagine something as fundamental to computing as the sudo command becoming abandonware, yet here we are: its solitary maintainer is asking for help to keep the project alive.

Archived version

    • Scrollone@feddit.it
      link
      fedilink
      arrow-up
      19
      arrow-down
      1
      ·
      12 hours ago

      To be honest, it wouldn’t take much for distro maintainers to detect that and stop it

      • JustEnoughDucks@feddit.nl
        link
        fedilink
        arrow-up
        3
        arrow-down
        1
        ·
        3 hours ago

        But who is seriously looking at the sudo code at every update. I would bet a lot of money that the vast majority simply trust him and gloss over it maximum.

        The chain of trust has to exist otherwise distrobox maintainers would spend 24 hours a day reviewing code changes and only update once every 6 months.

        • da_cow (she/her)@feddit.org
          link
          fedilink
          arrow-up
          2
          ·
          41 minutes ago

          You may want to look into how the xz backdoor has been discovered. That backdoor was very well hidden. Implementing a crypto mining malware would be blatantly obvious and yes, people do in fact look at such code