4 ms·
At the time they hadn't and I'm fed up of the jumping to conclusions that env vars are the cause of any security issue. This is blaming poor code from poor devs
by rob_c 1y ago
At the time they hadn't and I'm fed up of the jumping to conclusions that env vars are the cause of any security issue. This is blaming poor code from poor devs on expert features from UNIX all to often.
Worrying when said person has authored a widely used security product(!). This is a bad trend in the industry that needs to stop.
- Dylan16807 1y ago> At the time they hadn't Their comment was before yours.
- rob_c 1y agoif that's the comment you mean, it also misses the point
- Dylan16807 1y agohttps://news.ycombinator.com/item?id=44355306 https://news.ycombinator.com/item?id=44355306 I'm talking about this comment. Are you talking about this comment? From what knowledge I have, it looks like a good explanation of the problem and why it's not an environment variable problem.
- mkj 1y agoI'll say it again - environment variables or pam_env aren't expert features - they're primitive. They were a contributing factor in the first privilege escalation.
- rob_c 1y agoHardly, it's a minor coding bug to do with defaults.