正在加载视频...
视频加载失败
Multiple Vulnerabilities Found in Rust Sudo Clone in Ubuntu Ubuntu is now shipping with Rust based replacements of core utilities (sudo, date, du, etc.). And the steady stream of bugs, missing functionality, and security vulnerabilities continues.
18,917 次观看 • 10 个月前 •via X (Twitter)
27 条评论

2025 guide to grifting with Rust - abuse your position to force replace trusted tool with slop - capitalize user base of original software - intentionally lower security - *users get breached* - pretend you care & sell endpoint security services - rinse & repeat

By citing bugs in the Rust implementation, Lunduke attempts to convey the idea that the official sudo implementation is stable, omitting the fact that even this official implementation still presents CVE vulnerabilities after many years of use. Below are the most recent CVEs, from months ago: Similarly, GNU Coreutil utilities also have recent CVEs:

"They did it by making the single worst strategic mistake that any software company can make: They decided to rewrite the code from scratch." -Joel on Software April 2000, discussing Netscape's total loss of marketshare

Stop being a bigot. You need to think about the Rust implementations as diverse, equitable and inclusive. Therefore, no matter how bad they are, you are wrong! Consider this your penance for decades of demanding dependability. 😅

What the world needs is an #Ubuntu #PPA containing the current #GNU #Coreutils recompiled using Fil-C for all supported architectures and (LTS) releases. In a second step, #Debian packages could be added to the mix as well. Any takers? 😁

this Rust fever bullshits thing, reminds me on 2014s era where all people had JS fever including Microsoft. They once wrote their Azure tool with JS, but in 2016 due to the complicated and buggy nature, they switch to Python.

So the myth and the hype is that security vulnerabilities result from the platform 'not being memory safe'.

Not surprised

But...but...but Rush has no bugs

the problem I see here is that these activists pushing Rust everywhere are doing long-term damage to an actually good language

Ubuntu recommendations are being auto-detected as spam:

Honestly the missing functionality is the most annoying part and is hard proof of the fact that this crap is pushed solely because of cronyism, nothing more.

Anyone with a room temperature IQ knows you dont release beta code into a production environment.

Would you cover a fresh Linux Foundation conference about 65k Rust in the kernel?

It'll all work out

I confirm you could rewrite all of them in pascal, and it would come out great. FPC is a great Open Source cross-target compiler.

Bug? in a rust code? No way🤯

Those people should be kicked out. This was so obvious from the start. The only thing they did was brake things

It should be pronounced sue-doo. think of it as "substitute user do"

A vuln in date i will be embarassed.

I already disable sudo on all my Linux machines, because I won't use one password for both user and root functions. Now this drops? There is zero chance I use sudo now. Just, no.

Color me shocked, LOL

they have a change to replace sudo with doas but then they say let rewrite coreutils. Bad ubuntu

I'm interested in hearing more about SquareFluggin. Where can I get some of that?

will fix this

if only someone could have foreseen this before making such a retarded decision

@NeedsArNS assign rust-coreutils-fail






