What’s up today? (Part 1)

Doesn’t seem to work on mine:

$ sudo -uid '#4294967295' /bin/echo "dear god i'm fucked"
sudo: unknown user: id
sudo: unable to initialize policy plugin

Edit: I should’ve read the article first. My sudoers file doesn’t have a rule that would makes this attack possible.

3 Likes

If you have access to enough computers with shell access by some other means (less specific exploits), you’ll find a few where sudo is in fact used this way.

Yes, it really depends if there is a distribution or a ‘common’ practice with a couple of specific programs that are defined this way in /etc/sudoers.
Extra difficulty for the hacker is that /etc/sudoers is normally only readable for the root user, so you also have to try the correct program.
Edit: Linux security hole: Much sudo about nothing | ZDNET

1 Like

That isn’t all that difficult though. There’s a limited number of cases when this particular use for sudo makes sense and that narrows down what’s worth trying. Moreover, since this exploit assumes you already have shell access, it also means you can just try everything that’s executable. I’m not sure I’m correct but the article says PAM session modules aren’t run so maybe you wouldn’t even leave an auth trail. But I’m not familiar with it enough to say for sure.

1 Like
1 Like

Who wants to read this and TLDR for us?

4 Likes

It sounds remarkably similar to what has already been achieved with Algorand, specifically the concept of sortition

4 Likes

Claiming hindsight really. If indeed the experiments had shown life then NASA would have been all over it because it would have guaranteed funding for a whole lot more missions to mars. It would have been the biggest news to hit the papers to have confirmed life on mars and the biggest funding boost NASA would have gotten

Basically it was a result that could have been because of life, but could have been other things. We today know the thermal vents under the oceans produce similar results but life only occurred after. So basically the 1970 results showed that life maybe there because of the result, not proven nor necessarily a normal result as other things may be needed for life to occur later. Then a repeat of the experiment did not reproduce the result. It was one result out of many.

Science says you have to be able to reproduce results. They could not. Sometimes people say things later in life to give themselves that sense of extra importance. It seems that if the conclusions this scientist says now is entirely correct then NASA would have had pretty much as funding as it could have handled for mars probes/robots for a few decades back then.

1 Like
5 Likes

@Nadia do you know if this applies to MaidSafe?

Who this applies to

Any business which undertakes or expects to undertake the cryptoasset activities identified in the Treasury 2019 consultation paper

I could be wrong of course, but isn’t this talking of businesses like exchanges, escrow, payments systems (eg crypto ATMs, POS systems) and other financial style of things

SAFE is more like a network game with tokens used to purchase resources or the player is rewarded with them. And it is up to the exchanges that deal with safecoin tokens to do their own registrations. The SAFE network at no time deals with fiat or payment systems. The APPs running on safe will definitely have to consider registration if they do.

But yes @Nadia this was asked before if there is something Maidsafe has to deal with because of the Anti Money Laundering rules the previous post relates to.

1 Like

It might apply to maidsafe after 2020. Any open source provider of code that can be used for crypto coins will be affected. It looks like a tax on crypto related business disguised as a way to pay for a policing of the sphere. So the good guys pay for these people to police them, typically british these days, unfortunately :wink: Something should happen, pity it is not gonna be something supportive and forward looking but instead presumed guilt and terror (very british in fact :wink: )

12 Likes

A not-for-profit project building a collaborative, online directory of ethical companies - SAFE has of course been mentioned :stuck_out_tongue_closed_eyes:

11 Likes

Was a bad idea in the first place!

1 Like

:stuck_out_tongue:

3 Likes

What do you guys think of this? https://twitter.com/bronzejaguar/status/1184313081272254469

5 Likes

They say they’ve found the fastest ants on the planet, but they haven’t been to Ayr:

10 Likes