18 ms·
Todd C. Miller – Sudo maintainer for over 30 years
- wodniok 8mo agoQuote from Website: "For the past 30+ years I’ve been the maintainer of sudo. I’m currently in search of a sponsor to fund continued sudo maintenance and development. If you or your organization is interested in sponsoring sudo, please let me know."
- stego-tech 8mo agoThis is why Big Tech is so desperate for AI to work as a wholesale replacement for software developers: they do not pay for their Open Source consumption as-is, and new maintainers aren’t stepping up because they can’t afford rent, let alone to devote their full time to FOSS work free of charge like a lot of older project maintainers do. The fact that sudo is a critical security pillar for trillions of dollars of global infrastructure but this guy gets bupkis for it screams volumes about the current state of technology. We must do better, or it’ll be closed systems (OpenAI, Microsoft, Apple, Google, Oracle) all the way down as maintainers age out, go bankrupt, or die without succession plans in place.
- palmotea 8mo agoHonestly, it seems like the idealism of open source shouldn't have survived its contact with capitalism, but I suppose the contact wasn't painful enough the the exploitation continued for a long time. Maybe we need a license that's even more onerous to corporations than the AGPL, like something with a revenue share clause. Or maybe the problem is the naivete of software engineers. In aggregate, there was so much embrace of libertarianism that no groundwork was laid to protect ourselves from things like AI and offshoring.
- stego-tech 8mo agoBeen pitching that with my FOSS colleagues and peers for years, now. A license for individual and educational use, but pay-to-play for anyone tangentially making revenue from its use. Then the conversation boils down to the business engineering of how much should something cost, with some arguing for flat yearly rates, and others arguing for cost-per-unit, while others still fret about "disrupting" the status quo immediately after acknowledging its untenability. It's...frustrating, but those who do the work are the most qualified to explain what they need. For the rest of us, it's encouraging them to seek reasonable compensation for their work from those who exploit it for profit, and that doing so doesn't necessarily go against the spirit of open source.
- calvinmorrison 8mo agocan't wait for popularity-contest(1) to be mandatory and required a linked credit card.
- acuozzo 8mo ago> the idealism of open source shouldn't have survived its contact with capitalism The US economy of the 1980s, 1990s, and 2000s made it possible.
- softfalcon 8mo agoI don't mean to come across as far too cynical, but in what world has a software license ever stopped the greedy and powerful from pillaging the IP of other people smaller and weaker than them? In my opinion, libertarianism in software is a hollow dream that leads people to make foolish decisions that can't be protected. This makes it easy for corporations to exploit and quash any barely audible opposition. Almost as if by plan, the libertarian mindset has eroded and weakened open source protections, defanging and declawing it every step of the way.
- htx80nerd 8mo ago>"it screams volumes about the current state of technology." about the current state of Big Corp vampires who are happy to bleed everyone dry to put more $$ in their own very fat pockets
- softfalcon 8mo agoExactly
- functionmouse 8mo agoOur economic system starves you to death if you don't People aren't vampires because they're on top, they're on top because they're vampires. Shit flows downstream
- whatis991 8mo agoA change in economic system might be neither sufficient nor necessary, especially if the new economic system turns out to be even worse, or a scam. One approach is to have expectations to not only the economic system, but also other systems, and the different people involved, no matter if they're on the top, on the bottom, or somewhere in the middle.
- softfalcon 8mo agoSounds like the system is working as intended... Not trying to be glib here. This feels like the embrace, extend, extinguish pattern that we jokingly used to think was only Microsoft. It is now becoming more and more obviously the modus operandi of the entire enterprise software ecosystem. I believe you are correct to be frustrated and ringing the alarm bell. This is a "death of the commons" moment for OSS.
- drnick1 8mo ago> and new maintainers aren’t stepping up because they can’t afford rent, let alone to devote their full time to FOSS work free of charge like a lot of older project maintainers do. What about the Rust rewrite (sudo-rs)? I think it shows people are interested in maintaining and/or modernizing tools taken for granted.
- whatis991 8mo agoIt has a more lax license AFAIK. Also, many Rust projects and libraries have been abandoned, or are in so-so shapes. Edit: To specify, new projects like sudo-rs may seem promising, but going by observation and experience with similar projects, there is no guarantee that sudo-rs and similar projects will be successful, good and continued to be maintained. The problems with old projects can end up applying to new projects as well. And projects in Rust are no exception, going by experience with existing, older Rust projects. Aside, a pet peeve I have is that for instance Ruffle has not turned out as successful as I had hoped for, even after several years and many sponsors. The proprietary Flash runtimes written in C still outperform Ruffle greatly in some cases, causing problems for some users that want to use Ruffle instead of other runtimes.
- aw1621107 8mo ago> Also, many Rust projects and libraries have been abandoned, or are in so-so shapes. This seems like a bit of a non-sequitur; the state of non-sudo-rs projects/libraries says nothing about the state of sudo-rs itself. Not to mention that I'd imagine a similar statement would probably be true for projects and libraries written in any reasonably popular language.
- fragmede 8mo agoIf there are 1000 projects that aren't sudo-rs but are similarly load bearing, and they have all been abandoned/in so-so shape, you're right that it doesn't actually say anything about sudo-rs, but there's a highly probable outcome that will be inferred by most people. Incorrectly or otherwise.
- 8mo ago
- whatis991 8mo agoThis might be a controversial view: What if the exploitative aspect is open source itself? Trick some above average but naive developers into giving their talent, effort, insights and time away for free or very little? Maybe open source or something similar could have been organized in a way that wasn't exploitative and wasn't (possibly) unsustainable, but that is not how things ended up with what Richard Stallman and others organized.
- markus_zhang 8mo agoI think at least the license should say something like we will charge on a per CPU or whatever basis for commercial usage. You give it away for free so don’t be surprised to get abused. Human nature working at its best and worst here.
- monero-xmr 8mo agoThe exact moment you charge for something, you need payment processing, a bank, a legal entity to hold said processed funds, you have liability, you need some sort of marketing / sales process (even if it's just copy on a website), and the barrier for someone to use your product is suddenly extremely high, simply because it costs something. Release it for free, no barrier to entry, no legal liability, the entire world can use it instantly. This is why free software spreads and catches on - precisely because it's free. There is no way to form a business around FOSS without becoming a gatekeeping high-barrier entity. You can release for free then charge extra for consulting or special features, which many have done and continue to experiment with. But the core reason why FOSS spreads and took over is precisely why it is difficult to fund. No one is going to pay for something when the alternative is free. And the moment you start to charge some free alternative comes along and your prior users spurn you as greedy
- whatis991 8mo agoI think you have good arguments, but I wonder if there are alternatives that could work in at least some cases. Like, how Unreal engine's license works. Source-available to game developers, but in theory limited to paying customers, or something along those lines.
- SoftTalker 8mo agoWhy should something like sudo not be "done" after 30 years? Sudo is one of the poster children for creeping featuritis, to the point that the sudoers man page is a meme ("Don't despair if you are unfamiliar with EBNF ...") Even OpenBSD gave up and implmented their own simplified replacement (doas).
- asveikau 8mo agoThis community and others like it are so weird in that if they see something as stable as sudo but without recent commits, rather than conclude that it's solid and doesn't need further changes, they see it as some kind of a problem and want to switch to something that's seen major changes in the last week. Maybe that's somehow related to why so many companies are shoving AI into a bunch of stuff that doesn't need it. Gotta keep everything on the hype train. Working and fulfilling people's needs is no longer good enough.
- catdog 8mo agoThe thing is, there is next to no software that "doesn't need further changes" at all. There is always something, sure it might be infrequent and/or most of the time nothing really big or difficult (except sometimes) but the point is: someone needs to step up and do it. If a see a project with recent activity, best from multiple people it is a strong signal that this will happen, if the last commit is a year ago I must assume it's completely abandoned because most of the time it just is. Sometimes it's clearly communicated that it is the way because the authors see it as essentially feature complete, there are some examples of this but not that many honestly.
- blame-troi 8mo agoDifferent platform but the simplest mainframe utility IEFBR14, a noop process to trigger JCL events started as one instruction. Then two. Then debate started about which machine instruction should be used to set the return code to zero …
- pjsg 8mo ago
- arccy 8mo agomaintainers need to learn to say "no" to scope creep and entitled users. sudo should have been a near complete tool after it was written.
- sllabres 8mo agoSo no #includedir, no LDAP integration, no log_input/output, no PAM integration ...?
- pwndByDeath 8mo agoI've always favored the view that digital goods are only scarce until they are released. if we had a market for patch releases once they hit some goal. Uses could tip to reach the goal. After the goal is reached the patch is released and to all. Still have free loaders but one might live on the work
- WorkerBee28474 8mo agoSo...crowdfunding via a platform like Kickstarter?
- akokanka 8mo agoHave used sudo millions of times. It's so smooth I don't even consider it software. Thinking that sudo could give me bug one day haunts me now. Thanks Miller for your work!
- amelius 8mo agoI still think the integration with X11 $DISPLAY could be smoother.
- jmclnx 8mo agoI would love to know were IBM is on this. They use sudo everywhere, even on AIX. Not to mention IBM owns Red Hat Linux. IBM should be able to send a decent amount to Todd once in a while, but based upon how much IBM supports ssh ($0), all they are proving is they are very cheap and only wants be a parasite living off other's work.
- fdupress 8mo agoSeeing the server temperatures go up as this gets posted to HN is fun. I'm not sure his server agrees.
- divbzero 8mo ago“Machine Room Temperature” from Todd C. Miller’s website: https://www.millert.dev/therm/ https://www.millert.dev/therm/ Server exhaust fan temperature was typically 94°F (ranged 92°F to 96°F) over the previous week and has climbed to 97°F.
- divbzero 8mo agoBut, on the whole, the server seems to be doing well enough for something near the top of HN. The website is served by nginx and appears to be mostly static pages.
- calvinmorrison 8mo agoI once wrote hacking is ethical. Maybe I meant 'eventual'. Instead of Red-Hat sponsoring sudo, china can sponsor him to put hacks in.
- kleiba 8mo agoObligatory xkcd: https://xkcd.com/2347/ https://xkcd.com/2347/
- kleiba 8mo ago...although this one would have been a good fit too, of course: https://xkcd.com/149/ https://xkcd.com/149/
- zerotolerance 8mo agoBut today people can just vibe code their own sudo "with blackjack and hookers!" /s Really though, it is remarkable just how high we've built this towering house of cards on the selfless works of individuals. The geek in me immediately begins meditating on OSS funding mechanisms I've seen in the past, and what might work today. Then I remember that I don't believe it can work, but hope desperately that people like Todd can keep paying rent and continue getting some satisfaction from the efforts.
- OsamaJaber 8mo ago30+ years maintaining one of the most critical pieces of infrastructure on nearly every Linux and Unix system, and he's currently looking for a sponsor to fund continued development. Every company running sudo in production owes this man. Someone should fix that
- boringg 8mo agoRight? A company to step and cut a check to support this would get positive publicity and there doing something good for community at large. Someone step up.
- lovich 8mo agoCompanies don’t step up and do things for the common good. They do things for profit. Occasionally that looks like they are charitable if the value of the PR is worth it for them. No one[1] changes what product they are using based on funding or not of open source software. Companies will step in and fund it if they want control, like with Rust, or if the maintainer finally stops giving them free labor and they actually need the software. [1] not enough people to alter finances
- oconnore 8mo agoWhy would you be running sudo in production? A production environment should usually be setup up properly with explicit roles and normal access control. Sudo is kind of a UX tool for user sessions where the user fundamentally can do things that require admin/root privileges but they don't trust themselves not to fat finger things so we add some friction. That friction is not really a security layer, it's a UX layer against fat fingering. I know there is more to sudo if you really go deep on it, but the above is what 99+% of users are doing with it. If you're using sudo as a sort of framework for building setuid-like tooling, then this does not apply to you.
- acdha 8mo ago> A production environment should usually be setup up properly with explicit roles and normal access control. … and sudo is a common tool for doing that so you can do things like say members of this group can restart a specific service or trigger a task as a service user without otherwise giving them root. Yes, there are many other ways to accomplish that goal but it seems odd to criticize a tool being used for its original purpose.
- jandrese 8mo agoHonestly he should open a Patreon. There are loads of people that would subscribe to Sudo for $2/month or $5/month.
- rileymat2 8mo agoThe problem is if I was going to do that with the open source projects I use, it is more like a penny a month * 1000 projects.
- bobmcnamara 8mo ago$.01/user/month would be quite a bit here
- einsteinx2 8mo agoSubtract the standard ~3 cent transaction fee and he’d end up owing money instead. That seems to always be the catch with micropayment ideas.
- __turbobrew__ 8mo agoSounds like we need an open source index fund where you can make one payment that goes into a pool of money which is invested into the top 1000 open source projects.
- aftbit 8mo ago
- fHr 8mo agoUnbelievable, every fortune 500 company should sponsor this you all rely and use this. This makes me so sad I hope this has a good end.
- dwflanagan 8mo agosudo pay him
- anigbrowl 8mo agoI've said it before, open source works poorly in this area. It's great if everyone's getting paid fat money in a day job and can maintain their pet project a few days a month, but that's just not true for a lot of people. It's disgusting that maintainers of critical projects have to go through the humiliation of begging for money, and absurd to suggest they all hang out Kofi or PAtreon banners. Realistically nobody is going to go through their bash history working out what utilities they use in order of frequency and allocating funds to the maintainers proportionally. I'm baffled that some entity like the Linux Software Foundation isn't administering this already.
- fragmede 8mo ago> Realistically nobody is going to go through their bash history working out what utilities they use in order of frequency and allocating funds to the maintainers proportionally. Not if we don't make it easy for them. I had Claude whip up fundcli a while ago, but this post got me to finally upload it. It goes through your http://atuin.sh/ http://atuin.sh/ history (raw .bash_history/.*history doesn't have enough information) and generates links to projects for you to donate to. git clone https://github.com/fragmede/fundcli uv run src/fundcli/cli.py analyze uv run ./src/fundcli donate --amount 100 to get links to donate $100 for last month's usage. There's also http://thanks.dev http://thanks.dev if you're looking for other places to donate to based on your open source usage.
- jongjong 8mo agoI feel like this should have been the responsibility of investors and venture capitalists. In a normal society, the moneyed folks should give special treatment to the folks who have proven themselves to be effective givers. Unfortunately, it seems like either the moneyed folks don't care or the current financial structure simply does not support this.
- badsectoracula 8mo agoI think that's because the moneyed folks tend to be effective takers :-P
- 8mo ago
- shevy-java 8mo agoThe funding problem is an issue. We need to find better models. Even if it is just "low(er)" payment; that would still be better than zero or near zero payment.
- larodi 8mo agoUniversal Global Contributor Wellness Fund may also fund retirements for certain individuals, and there is for sure enough free juice to get it started in a very reasonable way. these people really deserve it, the same way Nobels extist, etc.
- dangoodmanUT 8mo agoImpressive but the mascot for sudo is terrifying
- ahartmetz 8mo agoBut also quite funny when you make the connection!
- hobofan 8mo agoPerpetuating misogyny as the mascot of one of the most used pieces of software. Yay!
- ahartmetz 8mo agoLook again at the xkcd comic (I did before posting the comment). The sandwich-making person is not obviously female, in fact he(?) looks rather male according to xkcd convention.
- hobofan 8mo ago"make me a sandwich" has been a saying to dismiss women for decades before the xkcd comic existed.
- metalliqaz 8mo agoThis kind of thing is why the left always loses. If you want to win, people have to like you.
- dannyw 8mo agoContext always matters. Phrases can also be normalized through everyday use without the negative connections.
- thelastgallon 8mo agoThere's also NTP. The Largely Untold Story Of How One Guy In California Keeps The World’s Computers Running On The Right Time Zone: https://onezero.medium.com/the-largely-untold-story-of-how-one-guy-in-california-keeps-the-worlds-computers-on-the-right-time-a97a5493bf73 https://onezero.medium.com/the-largely-untold-story-of-how-o... https://xkcd.com/2347/ https://xkcd.com/2347/
- debo_ 8mo agoYou forgot the more relevant: https://xkcd.com/149/ https://xkcd.com/149/
- ryandrake 8mo agoReading the release history[1]. I'm kind of shocked that sudo gets active development and monthly releases. I would have thought that something this old and venerated would have been "done" long ago. 1: https://www.sudo.ws/releases/devel/ https://www.sudo.ws/releases/devel/
- hobofan 8mo ago"Done" software is a myth they tell to young developers so that they can sleep easy at night.
- kachapopopow 8mo agowireguard is relatively "done"
- imchillyb 8mo ago"relatively" is just a word added to done and the fact that there is a qualifier precludes the word from bearing truth.
- yjftsjthsd-h 8mo agoOut of curiosity, what changes would it have at this point?
- hobofan 8mo agoI'm not intimately familiar with Wireguard, but there are some things that are almost universally applicable: - It should run on an maintained OS (which should run on available hardware), so whatever changes are necessary to keep pace with that - It may want to add optimizations regarding newer CPU architectures - It uses a compiler, so whatever changes necessary to stay on a maintained version of the compiler - It uses cryptography, so whatever changes necessary to stay up to date with latest cryptographic research to provide a secure solution, as well as updating cryptographic libraries to not be exposed to CVEs found in them. It also exists in the context of one/multiple jurisdictions, so possibly also changes to comply with interference in sound cryptography (let's hope not). And all of those are just part of the things to keep up with the world around you evolving. Of course there may also be bugs to fix in the code itself, and/or new ones created by doing any of the changes above. Even their definition of "complete"[0] includes "active maintenance" and "still much to do". [0]: https://www.wireguard.com/repositories/ https://www.wireguard.com/repositories/
- arjie 8mo agoI think the rise of the open-source redistributor groupie has been an interesting cultural revolution. I wonder if it will persist. Even 10 years ago, the idea of Free As In Speech dominated the idea of Free Software. Today, the greatest enthusiasm on Hacker News and Reddit is for something like Meta's Llama license (which cannot be used by people or corps with sufficient numbers of users). It certainly seems like someone out there could go out and propose the Microfree License which only applies to sufficiently non-rich people. For my part, I want none of it. I find this reduction of a significant philosophy to some kind of base tax-and-distribute mechanism distasteful. I don't like communities were this stuff is big and they always want to run some taxation scheme where they redirect money to their own personal pet projects. It is fortunate that modern tools are good enough to build personal insulation from this stuff. Imagine the farce of Apply HN repeated continuously. Simply awful.
- deleted 8mo ago[deleted]
- debo_ 8mo agoSomeone make this man a sandwich. https://xkcd.com/149/ https://xkcd.com/149/
- baggy_trough 8mo agosystemd, as might be expected, has a sudo replacement in recent versions, for those who think sudo might be a bit long in the tooth: run0 https://www.freedesktop.org/software/systemd/man/256/run0.html https://www.freedesktop.org/software/systemd/man/256/run0.ht...
- gsich 8mo ago[flagged]
- h4kunamata 8mo agoCanonical tried to change that with sudo-rs, but by being Canonical they did what Canonical do best since they got too big: Read poop here
- gwbas1c 8mo ago> Halloween `91 with Todd as the infamous Ducktape Man! https://www.millert.dev/images/photos/todd_ducktape_man.gif https://www.millert.dev/images/photos/todd_ducktape_man.gif Uhm, how did Todd relieve himself in that costume?
- cr125rider 8mo agoThis is the guy in the XKCD comic holding up the entire stack.
- DonHopkins 8mo agoLet's sudo and say we didn't.
- RickJWagner 8mo agoTodd C. Miller, thank you for your contributions. Sudo is an awesome piece of work.
- heftykoo 8mo agoIt's genuinely terrifying to think how much of the modern internet rests on the shoulders of a few people maintaining core utilities like sudo, curl, and openssl for decades. Todd is a legend.
- rixed 8mo agoYes but that would be even more terrifying if it rested on the whims of some soulless corporation.
- redog 8mo agoms-sudo to Get-AdministratorPermissionForElevatedSecurityOperations
- dannyw 8mo ago0xEFF0332: Operation could not be performed due to missing TPM flag.
- mayhemducks 8mo agoLOL sob
- khaki54 8mo agoI think xkcd should fund it, that would be comical.
- ilaksh 8mo agohttps://github.com/sponsors/sudo-project https://github.com/sponsors/sudo-project Can donate there. My bank account is basically empty but I will contribute a few bucks.
- egorfine 8mo agoContributed immediately. Thanks to sudo-rs: this stolen valor project made me want to financially support the original author.
- zbentley 8mo agohow does the metaphor of stolen valor (in my understanding: claiming accolades or military credentials/decorations that one never received) apply to that project? I don’t know anything about the history here; it’s a genuine question.
- egorfine 8mo agoAuthors of useless rewrites do: * skip the hard part: designing, getting user feedback and designing again; * get straight to the fun part: coding in their favorite language after a well-established and proven design; * get to call themselves "creator of XXX-rs", where "XXX" is a well-known brand and "-rs" is often overlooked.
- ginsider_oaks 8mo agowould it be better if they didn't skip the hard part? (i.e. if they re-designed it from first principles) does something being hard to do make it more virtuous? would it be better if they didn't have fun coding it? is something worse if it was fun to make?
- zbentley 8mo agoI meannnnnn… Pedantically, the “stolen valor” metaphor absolutely doesn’t fit here; you’re just griping about the “sudo brand” being used in another project’s title (which … citation needed, and so what? Is “doas” not committing theft but “sudo-improved” is?) More generally, that’s an easy case to make against any software you don’t like: “it’s just reimplementing $whatever and trying to pretend to be the original therefore it’s unethical”. Some rewrites are good, and a huge benefit of the act of rewriting is that you do have a clear blueprint and understanding of the requirements (hell, Linux was a rewrite). Should the original creators of a thing be the only people who can ethically rewrite it? Where’s the line here?
- b2ccb2 8mo agoA good time to advertise for Sudo Mastery by Michael W. Lucas, highly recommend it if you want to dig in a bit deeper.
- chr1ss_code 8mo agoThank you :)
- jacquesm 8mo agoDoes he live in Nevada, by chance?
- arkensaw 8mo agoIt never even occurred to me that sudo was something people had to maintain. it's always just been part of linux
- dewey 8mo agoAnd Linux is maintained by who?
- theGeatZhopa 8mo agosudo contribute --bank --amount
- sodimel 8mo agoDidn't knew that sudo had a website with a... somewhat interesting logo: https://www.sudo.ws/ https://www.sudo.ws/
- zeroping 8mo ago"This incident will be reported" (in /var/log/auth.log)
- philipwhiuk 8mo ago> Only enable the TLS listener by default if a TLS cert is specified. There's a TLS listener in sudo? This project seems to have a tonne of features it shouldn't.
- amai 8mo agoOnly recently sudo got copied by Microsoft for Windows 11: https://learn.microsoft.com/windows/advanced-settings/sudo/ https://learn.microsoft.com/windows/advanced-settings/sudo/ I guess they didn't pay a cent to Todd Miller.
- burkaman 8mo agohttps://github.com/microsoft/sudo?tab=readme-ov-file#relationship-to-sudo-on-unixlinux https://github.com/microsoft/sudo?tab=readme-ov-file#relatio... > This project is not a fork of the Unix/Linux sudo project, nor is it a port of that sudo project. Instead, Sudo for Windows is a Windows-specific implementation of the sudo concept.
- amai 8mo agoThey copied the name and the concept. The rest is probably AI-generated code.
- anon-3988 8mo agoif sudo needs 30 years of development, we need to rethink how it works. Perhaps it is time to trim down 99% of the features. Reset our brain, take a deep look at what it needs to do and how it does it.
- geldedus 8mo agoReferring to oneself to the a third person is a sign of narcissism ("Todd this, Todd that, Todd the other thing etc)"