Todd C. Miller – Sudo maintainer for over 30 years

millert.dev

406 points by wodniok 15 hours ago


ilaksh - 4 hours ago

https://github.com/sponsors/sudo-project

Can donate there.

My bank account is basically empty but I will contribute a few bucks.

ryandrake - 11 hours ago

Reading the release history[1]. I'm kind of shocked that sudo gets active development and monthly releases. I would have thought that something this old and venerated would have been "done" long ago.

1: https://www.sudo.ws/releases/devel/

arjie - 11 hours ago

I think the rise of the open-source redistributor groupie has been an interesting cultural revolution. I wonder if it will persist. Even 10 years ago, the idea of Free As In Speech dominated the idea of Free Software. Today, the greatest enthusiasm on Hacker News and Reddit is for something like Meta's Llama license (which cannot be used by people or corps with sufficient numbers of users). It certainly seems like someone out there could go out and propose the Microfree License which only applies to sufficiently non-rich people.

For my part, I want none of it. I find this reduction of a significant philosophy to some kind of base tax-and-distribute mechanism distasteful. I don't like communities were this stuff is big and they always want to run some taxation scheme where they redirect money to their own personal pet projects. It is fortunate that modern tools are good enough to build personal insulation from this stuff.

Imagine the farce of Apply HN repeated continuously. Simply awful.

OsamaJaber - 14 hours ago

30+ years maintaining one of the most critical pieces of infrastructure on nearly every Linux and Unix system, and he's currently looking for a sponsor to fund continued development. Every company running sudo in production owes this man. Someone should fix that

fdupress - 14 hours ago

Seeing the server temperatures go up as this gets posted to HN is fun. I'm not sure his server agrees.

heftykoo - 5 hours ago

It's genuinely terrifying to think how much of the modern internet rests on the shoulders of a few people maintaining core utilities like sudo, curl, and openssl for decades. Todd is a legend.

thelastgallon - 12 hours ago

There's also NTP.

The Largely Untold Story Of How One Guy In California Keeps The World’s Computers Running On The Right Time Zone: https://onezero.medium.com/the-largely-untold-story-of-how-o...

https://xkcd.com/2347/

akokanka - 14 hours ago

Have used sudo millions of times. It's so smooth I don't even consider it software. Thinking that sudo could give me bug one day haunts me now. Thanks Miller for your work!

dwflanagan - 12 hours ago

sudo pay him

RickJWagner - 6 hours ago

Todd C. Miller, thank you for your contributions. Sudo is an awesome piece of work.

anigbrowl - 12 hours ago

I've said it before, open source works poorly in this area. It's great if everyone's getting paid fat money in a day job and can maintain their pet project a few days a month, but that's just not true for a lot of people.

It's disgusting that maintainers of critical projects have to go through the humiliation of begging for money, and absurd to suggest they all hang out Kofi or PAtreon banners. Realistically nobody is going to go through their bash history working out what utilities they use in order of frequency and allocating funds to the maintainers proportionally. I'm baffled that some entity like the Linux Software Foundation isn't administering this already.

jmclnx - 14 hours ago

I would love to know were IBM is on this. They use sudo everywhere, even on AIX. Not to mention IBM owns Red Hat Linux.

IBM should be able to send a decent amount to Todd once in a while, but based upon how much IBM supports ssh ($0), all they are proving is they are very cheap and only wants be a parasite living off other's work.

jandrese - 14 hours ago

Honestly he should open a Patreon. There are loads of people that would subscribe to Sudo for $2/month or $5/month.

shevy-java - 12 hours ago

The funding problem is an issue.

We need to find better models. Even if it is just "low(er)" payment; that would still be better than zero or near zero payment.

gwbas1c - 10 hours ago

> Halloween `91 with Todd as the infamous Ducktape Man!

https://www.millert.dev/images/photos/todd_ducktape_man.gif

Uhm, how did Todd relieve himself in that costume?

baggy_trough - 10 hours ago

systemd, as might be expected, has a sudo replacement in recent versions, for those who think sudo might be a bit long in the tooth: run0

https://www.freedesktop.org/software/systemd/man/256/run0.ht...

khaki54 - 4 hours ago

I think xkcd should fund it, that would be comical.

cr125rider - 6 hours ago

This is the guy in the XKCD comic holding up the entire stack.

h4kunamata - 10 hours ago

Canonical tried to change that with sudo-rs, but by being Canonical they did what Canonical do best since they got too big: Read poop here

dangoodmanUT - 12 hours ago

Impressive

but the mascot for sudo is terrifying

DonHopkins - 6 hours ago

Let's sudo and say we didn't.

calvinmorrison - 14 hours ago

I once wrote hacking is ethical. Maybe I meant 'eventual'. Instead of Red-Hat sponsoring sudo, china can sponsor him to put hacks in.

debo_ - 11 hours ago

Someone make this man a sandwich.

https://xkcd.com/149/

kleiba - 14 hours ago

Obligatory xkcd: https://xkcd.com/2347/

fHr - 14 hours ago

Unbelievable, every fortune 500 company should sponsor this you all rely and use this. This makes me so sad I hope this has a good end.

stego-tech - 15 hours ago

This is why Big Tech is so desperate for AI to work as a wholesale replacement for software developers: they do not pay for their Open Source consumption as-is, and new maintainers aren’t stepping up because they can’t afford rent, let alone to devote their full time to FOSS work free of charge like a lot of older project maintainers do.

The fact that sudo is a critical security pillar for trillions of dollars of global infrastructure but this guy gets bupkis for it screams volumes about the current state of technology.

We must do better, or it’ll be closed systems (OpenAI, Microsoft, Apple, Google, Oracle) all the way down as maintainers age out, go bankrupt, or die without succession plans in place.

wodniok - 15 hours ago

Quote from Website: "For the past 30+ years I’ve been the maintainer of sudo. I’m currently in search of a sponsor to fund continued sudo maintenance and development. If you or your organization is interested in sponsoring sudo, please let me know."

zerotolerance - 14 hours ago

But today people can just vibe code their own sudo "with blackjack and hookers!"

/s

Really though, it is remarkable just how high we've built this towering house of cards on the selfless works of individuals. The geek in me immediately begins meditating on OSS funding mechanisms I've seen in the past, and what might work today. Then I remember that I don't believe it can work, but hope desperately that people like Todd can keep paying rent and continue getting some satisfaction from the efforts.

gsich - 10 hours ago

[flagged]