logoalt Hacker News

Ferret7446today at 2:15 AM2 repliesview on HN

That is one of many reasons to keep your dotfiles under version control.


Replies

lrvicktoday at 2:46 AM

Someone that can wrap your sudo binary can wrap you git binary too. Once your OS is compromised all bets are off.

lpribistoday at 2:26 AM

How would that help? Unless you happen to check the dotfiles git diff before running _anything_. I guess this could be put in prompt or some cron job to detect diffs but I bet absolutely nobody does this.