5 ms·
I don't think it's really fair to say that this has anything to do with Ubuntu Server at all, or that it reflects on Ubuntu's security. After all, this issue on
by jbstack 3y ago
I don't think it's really fair to say that this has anything to do with Ubuntu Server at all, or that it reflects on Ubuntu's security. After all, this issue only occurs if you decide to enable a sudo command for a user and, if you're doing that, it's on you to understand the risks; risks which you'd have to take into consideration regardless of the distro.
For example, if I told you that I've identified a security risk in giving sudo access to a user for the command "rm -rf /", would you conclude that Ubuntu is an insecure distro?
- phone8675309 3y agoIf Ubuntu Server shipped with a configuration out of the box that let a user run 'sudo rm -rf /' _by default_ then yes, I would conclude that Ubuntu is an insecure distro. Would you not?
- jchw 3y agoThe missing context is that I misinterpreted the article to mean that this sudoers rule was here by default. It's not... which makes this an entirely different story. I had an inkling that this was the case, but I was too busy to verify personally and by the time I had actually realized, it was too late to delete/edit the comment. Which makes this whole thing annoying. The article shouldn't be flagged, because there's nothing technically wrong with it. I just found it confusing, and I wonder if maybe part of the reason why it was deemed interesting enough to be propelled to the frontpage is due to similar misinterpretation. (After all, I would find it VERY interesting if this WAS a default.)