logoalt Hacker News

self_awarenesstoday at 5:51 AM1 replyview on HN

And how a malware can use this if it's configured globally in a root:root owned config file?


Replies

drdexebtjltoday at 6:05 AM

Not all package managers require root.

But yeah, maybe through an exploit with a narrow reach. Once in, the malware can veto security updates and escalate to full control.

show 1 reply