Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here before the haters. sudo was released around 1980. sudo-rs v. 0.2.0 was released in 2023. I suspect that in the next 2-5 years sudo-rs will be as safe and stable as sudo


If sudo is as stable as you say, which I’m sure it is, then why are we retiring it for a new rust version over several years which will allow extra security issues during that time?

Maybe writing things in rust is a good idea, but perhaps not stuff that’s already battle hardened, IMO.


> Maybe writing things in rust is a good idea, but perhaps not stuff that’s already battle hardened, IMO

Some people _love_ to learn the hard way, but some never learn. And, as someone said: "But that's what happens when there is no incentive for people to do the parts of programming that aren't fun. Fixing bugs isn't fun; going through the bug list isn't fun; but rewriting everything from scratch is fun (because "this time it will be done right", ha ha) and so that's what happens, over and over again. "


Even after 40 years of battle-hardening, it has had buffer overflow and double free vulnerabilities discovered recently, which Rust protects against. sudoedit one was pretty bad. https://www.sudo.ws/security/advisories/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: