sudo-rs' first security audit - Ferrous Systems

https://ferrous-systems.com/blog/sudo-rs-audit/

34 points · 3 comments · view on lemmy.world

3 Comments

BB_C@programming.dev · 7 pts · 2y (2 replies)

Should have told the auditors that stripping symbols is stupid and counterproductive instead of playing along. That segfault a user managed to hit once and only once with their self-built binary, and that useless core file that was left behind, shall hunt you in your dreams forever.

And I love how that commit was merged with the comment "A further reduced binary size! 🎉". Exhibit number #5464565465767 why caring that much about "dependency bloat" and binary sizes always was, and always will be, a result of collective mania in action.

fil@programming.dev · 2 pts · 2y

Conspiracy theory: the workgroup found an RCE vulnerability and assigned it identifier CLN-002 but never disclosed it to public and instead sold it to (CIA|DHL|MiB)