5 ms·
Honestly, that's even scarier for an untrusted/low trusted tool...
by unsnap_biceps 6d ago
Honestly, that's even scarier for an untrusted/low trusted tool...
- cstrahan 6d agoWhat is it about a tool, running as your own non-root user, installed in your home directory, that makes it scary?
- unsnap_biceps 5d agoLet's say this is widely used and let's presume that a specific version has a security issue. With everyone having their own copy of the binary on every host versioned at the time they first ran a command on that host, or any decently sized fleet, it'll take a big effort to track down and ensure all versions have been updated or removed (to be re-generated later). Frankly, we would re-kick our fleet ahead of schedule rather then try to remediate it more manually. But we re-kick our fleet on a rotating yearly schedule, so it's not too much an effort to re-kick it earlier. It's a completely automated system in place now.