@wxcafe@social.wxcafe.net human trusts in their $PATH to be nonpoisonous?
how funny
@lanodan_tmp @wxcafe@social.wxcafe.net people accidentally type their passwords into their shells and don't scrub it from ~/.[shell]_history i think expecting people to check that is asking a bit
@lanodan_tmp @wxcafe@social.wxcafe.net also, you didn't consider the possibility of "which where when why" all also being poisoned
once a competent enough attacker has control of your ~/.[shell]_profile, all they have to do is wait for you to mess up
@wxcafe@social.wxcafe.net what you dont know is your sudo has been redirecting to a sudo binary in a hidden directory in your $PATH that logs your password and passes it to sudo so sudo still works but it has your password