Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #56312

Re: Yet Another New systemd Feature

From D <nospam@example.net>
Newsgroups comp.os.linux.misc
Subject Re: Yet Another New systemd Feature
Date 2024-05-08 11:54 +0200
Organization i2pn2 (i2pn.org)
Message-ID <f8207b24-ce45-99b6-7106-c0e90441b3b7@example.net> (permalink)
References (2 earlier) <v1a3cbf08a@dont-email.me> <71362256743962b72394883a66a5504a@msgid.frell.theremailer.net> <v1db91$1hnge$1@news1.tnib.de> <c7674554-bbb0-cd6d-86ee-2abc5ed0e3a6@example.net> <v1e16r$1jc7c$1@news1.tnib.de>

Show all headers | View raw



On Tue, 7 May 2024, Marc Haber wrote:

> D <nospam@example.net> wrote:
>> Since you are the expert witness... what is the point of OpenBSD:s doas
>> instead of sudo? If the two were to battle to the death with the lirpa,
>> which one would win?
>
> runas is much simpler and thus has less attack surface. Sudo has a
> complex parser of a historically grown configuration file format, a
> plugin interface. I'd rather not have that in a suid root binary.
>
> When I took over sudo maintenance in Debian, I was strongly
> considering to migrate my own systems to doas because of the smaller
> attack surface, but than decided that I need to eat my own dog food
> and stayed with sudo.
>
> Greetings
> Marc
>

Great! =) Thank you very much for the information Marc!

Back to comp.os.linux.misc | Previous | NextPrevious in thread | Find similar


Thread

Re: Yet Another New systemd Feature Fritz Wuehler <fritz@spamexpire-202405.rodent.frell.theremailer.net> - 2024-05-07 14:40 +0200
  Re: Yet Another New systemd Feature Marc Haber <mh+usenetspam1118@zugschl.us> - 2024-05-07 15:45 +0200
    Re: Yet Another New systemd Feature D <nospam@example.net> - 2024-05-07 21:03 +0200
      Re: Yet Another New systemd Feature Marc Haber <mh+usenetspam1118@zugschl.us> - 2024-05-07 21:59 +0200
        Re: Yet Another New systemd Feature D <nospam@example.net> - 2024-05-08 11:54 +0200

csiph-web