Skip to content

Comment on Bringing Memory Safety to sudo and suparent

Comments

it is a complex piece of software

That's the problem. It shouldn't be. I hope the sudo-rs variant does better.

Actually, there's a point: doas is already smaller and safer, so it would probably be easier to port to a new language as well as having less attack surface in the first place. Of course, it's still necessary to work with sudo as well because it genuinely supports a lot more features and some of them are even useful, but if you want the low hanging fruit...

They should just replace /etc/sudoers.d with a Domain Specific Language ;) /s

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.