Live data from Hacker News

Malware Found in the Ubuntu Snap Store

linuxuprising.com

61–70 of 223 posts

Re: Malware Found in the Ubuntu Snap Store

#61
post #50

used a proprietary license Does the license actually mention it mines? I am reminded of a lot of "freemium"/"ad-supported"/etc. software that makes its author money via ads or whatever else --- and you agree to that if you read the license --- and it is a bit shady to name the miner 'systemd', but it seems rather overboard to call this "malware"... when I see that term I think of software that self-propagates and exf…

It would still look quite shady. It's also burning electricity, hogging your CPU and putting heat and stress onto your CPU which is way worse than just displaying an ad which costs literally nothing (or 1 or 2 cents for fetching a single png and link). I use one donationware app and it's cleanly marked it display an add and it's explained they fetch it from their own site via a dumb static image request on startup (i…

It would still look quite shady. It's also burning electricity, hogging your CPU and putting heat and stress onto your CPU

Like any other Electron based app...

Re: Malware Found in the Ubuntu Snap Store

#62

A Monero miner is one of the more innocuous forms of malware ,compared to a C&C trojan or a keylogger. Some websites will mine monero in the background. Because it's just a js script, it's not much different than a banner ad except it's less intrusive, yet somehow 'currency miner' has more negative connotations than 'ad server'. That is the downside of decentralized mining and asic resistance is you end up with a lot…

> Because it's just a js script, it's not much different than a banner ad except it's less intrusive

Tell that to your electricity provider

Re: Malware Found in the Ubuntu Snap Store

#63

The problem with snaps is that they didn't take security really seriously on desktop: https://www.zdnet.com/article/linux-expert-matthew-garrett-u... >"X has no real concept of different levels of application trust. Any application can register to receive keystrokes from any other application. Any application can inject fake key events into the input stream. An application that is otherwise confined by strong securit…

But this particular issue doesn't have anything to do with X!

Re: Malware Found in the Ubuntu Snap Store

#64

The problem with snaps is that they didn't take security really seriously on desktop: https://www.zdnet.com/article/linux-expert-matthew-garrett-u... >"X has no real concept of different levels of application trust. Any application can register to receive keystrokes from any other application. Any application can inject fake key events into the input stream. An application that is otherwise confined by strong securit…

In a typical linux distro all apps are run under the same user which means they can do whatever they want to each other and user's files. So X server being secure or not doesn't really change anything.

By the way Android, unlike Linux, runs every app under a different user account.

Re: Malware Found in the Ubuntu Snap Store

#66
post #3

Apple's strategy for their store looks better and better every day.

https://www.bankinfosecurity.com/apple-battles-app-store-mal...

From looking at the link, it looks like it just sends information from the device to a web server. It doesn't look like it would have access to anything that any other app wouldn't have access to without explicitly asking for the users permission.

Re: Malware Found in the Ubuntu Snap Store

#67
post #65

> Nicolas Tomb used a proprietary license for at least some of his snaps. For example, the 2048buntu snap was submitted as proprietary. The game in question, 2048, uses a MIT license No! MIT is not a proprietary license!

I don’t think that’s what they’re saying. The developer repackaged the MIT licensed game with the miner under his own, proprietary, license

Re: Malware Found in the Ubuntu Snap Store

#68
post #65

> Nicolas Tomb used a proprietary license for at least some of his snaps. For example, the 2048buntu snap was submitted as proprietary. The game in question, 2048, uses a MIT license No! MIT is not a proprietary license!

2048 = MIT 2048buntu = Proprietary

Re: Malware Found in the Ubuntu Snap Store

#69
post #65

> Nicolas Tomb used a proprietary license for at least some of his snaps. For example, the 2048buntu snap was submitted as proprietary. The game in question, 2048, uses a MIT license No! MIT is not a proprietary license!

The article doesn’t say it is. The snap uses a proprietary license which is possible since the game on which the snap is based uses MIT - which allows redistribution under a proprietary license.

Re: Malware Found in the Ubuntu Snap Store

#70
post #41

Unlike flahub where either original develop or flathub admins take control Canonical's Snapcraft literally says "Get published in minutes" Any random guy would publish his malware with near no review https://dashboard.snapcraft.io/snaps/ Yes, they maybe win the counter for published apps compared to flathub. Congratulations!

> Unlike flahub where either original develop or flathub admins take control

Is this actual policy? How do they determine who is the original developer?

Post reply on HN