Live data from Hacker News

Malware Found in the Ubuntu Snap Store

linuxuprising.com

121–130 of 223 posts

Re: Malware Found in the Ubuntu Snap Store

#121

It's only a matter of time before some major successful linux system attack is delivered via snap/flathub. Distributions and their package maintainers serve an important role. In the interests of consuming more & faster people seem to be ignoring that. I wish we had enough resources in the free softare community for all software to be packaged and maintained in the distributions by independent parties unaffiliated wi…

In theory you can have the last bit with flatpack (and perhaps snap), the issue here is auditing what goes in the repositories, not the package format.

Have you ever gone through the rigamarole of getting a project into a major distro like debian?

A bunch of the guidelines governing that process are simply unenforcable in a model where the developer builds and publishes the release.

I am not of the opinion that those rules are irrelevant to the stability and security of our systems.

There's a significant push to establish a more app-store model for linux distributions, taking the distributor largely out of the loop for software that isn't part of the base system.

This has both positive and negative consequences.

Today the negative consequences are largely hand-waved away with something along the lines of "containers will protect you".

Re: Malware Found in the Ubuntu Snap Store

#122
post #75

Earlier quoted context omitted.

Well as a lazy arch user i installed pacaur and just use official and AUR sources without much checking. It's just convenient that there's an AUR for everything

Be warned that malware like this is in the AUR all the time. It's so common it's not even newsworthy. They are usually pretty good at handling it though.

Any sources/articles for this?

Re: Malware Found in the Ubuntu Snap Store

#123
post #14

Earlier quoted context omitted.

> Does the name "Ubuntu Snap Store" carry a connotation that code is reviewed for malware by Ubuntu, the way that the Apple, Google, Amazon, etc. mobile app stores are? As far as I know, Apple is the only company that manually reviews the code of apps, and even they let some (in my opinion) malware through [1]. Everybody else just does some heuristic anti-malware checking and then publishes the app. 1: Uber was perma…

Apple doesn’t get the source code of apps. They check what apis you use so they can prevent you from using non public apis and they run some cursory checks. But there is a lot of crap on the App Store.

I really wish we had app stores actually require vendors to submit source code and build instructions so that the app store would build it themselves and publish it. Something like F-Droid even if the source code is not publicly available.

Re: Malware Found in the Ubuntu Snap Store

#124

This is exactly why you should not run random docker images and snaps. Docker images are also run as root in many cases. It is better to build app images from scratch and understand what exactly goes into the image.

Why not run random docker images? As far as I understand, docker container are pretty solid. Not super solid but solid enough.

I have used the following image[1] on a server of my old company where we had a problem and no one with privileges was available. It gives you a root shell. I added my public key to the authorized_keys of root.

[1] https://hub.docker.com/r/chrisfosterelli/rootplease/

Re: Malware Found in the Ubuntu Snap Store

#125
post #9

There is no review process or central restrictions on who can upload to the Ubuntu Snap Store, so in a sense, this isn't surprising. https://docs.snapcraft.io/build-snaps/publish Does the name "Ubuntu Snap Store" carry a connotation that code is reviewed for malware by Ubuntu, the way that the Apple, Google, Amazon, etc. mobile app stores are? Or does its presence in the software center app imply a connotation that i…

I like Arch's package management model, where sources are split into the official repositories, which are manually approved, and the AUR, which everyone knows are not officially endorsed or reviewed, and to check the sources and PKGBUILDS for anything sketchy before installing. The processes for installing from the two are also different enough that the user can't mistake one for the other: official packages are a pa…

> ... and the AUR, which everyone knows are not officially endorsed or reviewed ...

Uh, not everyone. I ran Manjaro for a bit and found that many of the things I ran were available via AUR. The usual thing I'd find in a search was usually something like: sudo pacman -Sy sudo pacman -S yaourt base-devel yaourt -Sy yaourt -S gpodder (That's the entire reply, BTW.) At some point I started to wonder what the provenance of these packages was and what the security implications were. I might have looked for information on the security risks of these packages but this is the first concrete claim I recall seeing about the subject. Probably a good thing I'm not running Manjaro any more.

I do run Ubuntu and have some snaps installed (Golang, VS code among others) and I'm now wondering if it would be possible for a malicious developer to substitute compromised snaps for the official ones. My understanding is that they update silently and automatically so I wouldn't even know about updates if I didn't check logs.

Re: Malware Found in the Ubuntu Snap Store

#126

Earlier quoted context omitted.

I like Arch's package management model, where sources are split into the official repositories, which are manually approved, and the AUR, which everyone knows are not officially endorsed or reviewed, and to check the sources and PKGBUILDS for anything sketchy before installing. The processes for installing from the two are also different enough that the user can't mistake one for the other: official packages are a pa…

> ... and the AUR, which everyone knows are not officially endorsed or reviewed ... Uh, not everyone. I ran Manjaro for a bit and found that many of the things I ran were available via AUR. The usual thing I'd find in a search was usually something like: sudo pacman -Sy sudo pacman -S yaourt base-devel yaourt -Sy yaourt -S gpodder (That's the entire reply, BTW.) At some point I started to wonder what the provenance o…

In ubuntu, it's even less obvious. Main, restricted, and universe are all checked together by apt, and treated the same

Re: Malware Found in the Ubuntu Snap Store

#127

Earlier quoted context omitted.

I like Arch's package management model, where sources are split into the official repositories, which are manually approved, and the AUR, which everyone knows are not officially endorsed or reviewed, and to check the sources and PKGBUILDS for anything sketchy before installing. The processes for installing from the two are also different enough that the user can't mistake one for the other: official packages are a pa…

> ... and the AUR, which everyone knows are not officially endorsed or reviewed ... Uh, not everyone. I ran Manjaro for a bit and found that many of the things I ran were available via AUR. The usual thing I'd find in a search was usually something like: sudo pacman -Sy sudo pacman -S yaourt base-devel yaourt -Sy yaourt -S gpodder (That's the entire reply, BTW.) At some point I started to wonder what the provenance o…

You can't install unofficial packages via pacman. And AFAIK none of the unofficial/AUR package managers, like yaourt, are in the official repositories so the point where you cross the line is very clear and distinct and any wiki guide to installing from the AUR makes it clear you are going into unofficial territory.

I haven't used Manjaro but they seem to intentionally hide the distinction between the official and unofficial repos, which is a bad idea.

Re: Malware Found in the Ubuntu Snap Store

#128
post #112
post #14

Earlier quoted context omitted.

> Does the name "Ubuntu Snap Store" carry a connotation that code is reviewed for malware by Ubuntu, the way that the Apple, Google, Amazon, etc. mobile app stores are? As far as I know, Apple is the only company that manually reviews the code of apps, and even they let some (in my opinion) malware through [1]. Everybody else just does some heuristic anti-malware checking and then publishes the app. 1: Uber was perma…

Firefox addons are reviewed. That's why malicious firefox addons are a lot less common than malicious chrome extensions.

Can confirm that Mozillas review process is the most sofisticated i’ve ever experienced. The good thing is that when they have something to complain you have a competent person on the other side that really helps you. Not like Apple who only send you some boilerplate to all your responses. The downside at Mozilla is that it takes them ages to even start the review, it took me once over 2 month to get my extension in their catalog.

Re: Malware Found in the Ubuntu Snap Store

#129
post #29

Earlier quoted context omitted.

>a simple game like that taking >100MB would make me suspicious Nah. Games often feature a bunch of textures and video and sound files. Bad compression or too high resolution on those is quite common, which is why games _are_ often that large. Also proprietary software usually ships a bunch of libraries - games often ship with a premade engine, which are also often quite large. As a datapoint, I have a copy of "Strat…

I remember the Facebook app being less than 20 megabytes in size half a decade ago. Now it’s almost half a gigabyte

For which platform? Google Play Store says the full Facebook app is 73 MB; Facebook Lite is 1.7 MB.

Re: Malware Found in the Ubuntu Snap Store

#130
post #84
post #59

Earlier quoted context omitted.

Which is crazy – with my own apps even after they’re packed with features I can barely get above 4MB. Going to 100x that? Insane.

One word: electron.

Ues, electron is in opposition to less is more. It’s an abuse of memory and hdd. How can someone invent such a bloatware product?
Post reply on HN