4 ms·
Before people are exploding, just don't run it as root. Give it minimal read permissions and it could be really useful without destroying anything.
by lfkdev 4y ago
Before people are exploding, just don't run it as root. Give it minimal read permissions and it could be really useful without destroying anything.
- benob 4y agoHow long before subtle prompts that generate "sudo rm -rf /" as a command are proposed?
- corobo 4y agoIf you don't need to auth your sudo attempts that's on you. I wouldn't be willing to use this program in any case, but yeah as the comment you responded to said - don't give it root.
- isp 4y ago"rm -rf ~" doesn't require root, and would do significant harm. Neat tech demo to run on a sandboxed VM, but I would strongly recommend against running this on a box you care about.
- cwillu 4y agoIndeed, nearly all of the harm that rm -rf / would do to me, is due to / including ~
- corobo 4y agoWhen you're right you're right. I got nothing in retort - I missed the forest for the trees there. Good point, well made.
- rvz 4y agoYeah, I bet than no-one would trust this thing to simply: 'Cleanup the home directory' and it just goes and does 'rm -rf ~/' silently. I don't see the use-case in something that have a very low trustworthiness and is in fact a solution looking for a problem but creates more problems than it solves.
- notpachet 4y ago> I don't see the use-case in something that have a very low trustworthiness and is in fact a solution looking for a problem but creates more problems than it solves. You just described the majority of tech projects.
- oefrha 4y agoAbout everything on my system that’s root:wheel is reproducible. It’s the ones not owned by root that I care about.
- usrbinbash 4y ago`rm -rf` can cause more than enough damage without touching anything that requires root permissions to delete
- jerpint 4y agoWithout root it wouldn’t work
- brianshaler 4y agoI'd be curious if you could intentionally direct it to do something malicious. While not guarantee, if it's not capable of violating your trust intentionally it hopefully reduces the likelihood of something inadvertent happening. Like, install and run it in a docker container and then ask it to escape the container and write to a temp file on the host.