Live data from Hacker News

Microsoft repo installed on all Raspberry Pi’s

reddit.com

21–30 of 30 posts

Re: Microsoft repo installed on all Raspberry Pi’s

#21
post #10

Raspberry Pi OS comes with a ton of stuff, among others, Minecraft or the "Pi Store". It is not a minimal building block for your custom hacked Linux firmware, it's what they provide so teachers can install the stuff and have kids use it without going to a console and editing sources.list first.

Perhaps they could create a separate version of the OS for educational use in schools.

Re: Microsoft repo installed on all Raspberry Pi’s

#22

Earlier quoted context omitted.

But this doesn't grant remote access to your system, and it's not like Microsoft will start shipping replacements of core packages over this repo.

Technically it does grant another avenue of supply chain attack... but if Microsoft run mirrors are being compromised then we probably have much bigger issues than some raspberry pis.

Considering the damage that can be done by botnets like Mirai, Raspberry Pis might be exactly what we should be worrting about.

Re: Microsoft repo installed on all Raspberry Pi’s

#23
post #2

Redmond got finally a root shell on your Pi :-)

This is not even remotely true. All they have is the information that somene at $IP is using Rpi. Granted, I'd prefer not to give them this info, but let's stick to the facts.

It also gives them the ability to override any package on your system with one they make. All they'd have to do is increase their version number beyond the one in the "real" repositories and Apt would automatically update to it by default.

So yes, in fact, it's quite true.

Re: Microsoft repo installed on all Raspberry Pi’s

#25

This feels like a huge overreaction. "(...) every time an install of Raspberry Pi OS is updated it will ping a Microsoft server. Microsoft will know you're using Raspberry Pi OS/likely Raspberry Pi owner and your IP address." How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. I imagine that Raspberry Pi OS is an distro meant for people who simply want things…

> How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. Yes, but it's you who usually manage those mirrors, not some guy deciding which mirrors your apt must query now and pushing it in a regular update without notice. I don't care if it's Microsoft or some obscure Chinese repo, but I think nobody should mess with your mirrors list or trust their keys in this wa…

If you don't want "some guy" deciding which APT mirrors you use, then don't use "some guy's" linux distribution

Re: Microsoft repo installed on all Raspberry Pi’s

#26

This feels like a huge overreaction. "(...) every time an install of Raspberry Pi OS is updated it will ping a Microsoft server. Microsoft will know you're using Raspberry Pi OS/likely Raspberry Pi owner and your IP address." How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. I imagine that Raspberry Pi OS is an distro meant for people who simply want things…

> How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. Yes, but it's you who usually manage those mirrors, not some guy deciding which mirrors your apt must query now and pushing it in a regular update without notice. I don't care if it's Microsoft or some obscure Chinese repo, but I think nobody should mess with your mirrors list or trust their keys in this wa…

> Yes, but it's you who usually manage those mirrors,

That's not true for most people.

Re: Microsoft repo installed on all Raspberry Pi’s

#27

To put this into perspective, I'd like to kbow how many repos and gpg keys are there already. If microsoft was added to dozens others, then this is a storm in a teacup. If it when from 2 to 3, then the change is more significant. Lets keep in mind that the central goal of PI OS is education, not security, privacy, sticking it to corporates, IoT, etc.

Raspberry Pi has many product lines for industrial and IOT usage, including the Compute Module where security and privacy are expected. The standard operating system for such systems tends to be Raspbian Lite now called (Raspberry Pi OS Lite), which is affected by this issue.

I think that if you are producing a real device based on a compute module, you should not be using Rasbian Lite, things like Arch, Ubunti core, etc. are more suited for the purpose.

There is no real iot-style security in Raspbian lite, so before you get mad pver microsoft eepo being added, toy should be sorting that out

Re: Microsoft repo installed on all Raspberry Pi’s

#28

Earlier quoted context omitted.

> How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. Yes, but it's you who usually manage those mirrors, not some guy deciding which mirrors your apt must query now and pushing it in a regular update without notice. I don't care if it's Microsoft or some obscure Chinese repo, but I think nobody should mess with your mirrors list or trust their keys in this wa…

If you don't want "some guy" deciding which APT mirrors you use, then don't use "some guy's" linux distribution

No, it doesn't work like that. You pay for something and you complain. Even if you don't. And if the guy doesn't like criticism, he can quit at any time.

Re: Microsoft repo installed on all Raspberry Pi’s

#29

Earlier quoted context omitted.

Raspberry Pi has many product lines for industrial and IOT usage, including the Compute Module where security and privacy are expected. The standard operating system for such systems tends to be Raspbian Lite now called (Raspberry Pi OS Lite), which is affected by this issue.

I think that if you are producing a real device based on a compute module, you should not be using Rasbian Lite, things like Arch, Ubunti core, etc. are more suited for the purpose. There is no real iot-style security in Raspbian lite, so before you get mad pver microsoft eepo being added, toy should be sorting that out

Why would somebody use Arch (a distribution with a rolling release) on a product?

Debian is a reasonably platform for such devices (though not the best due to the ~2 year release cycles, rather than eg, 10 years for CentOS distributions back when they were around). I do take the point that Ubuntu Core may be even more suitable, but Raspbian should work fine for many real world applications.

Re: Microsoft repo installed on all Raspberry Pi’s

#30

Earlier quoted context omitted.

This is not even remotely true. All they have is the information that somene at $IP is using Rpi. Granted, I'd prefer not to give them this info, but let's stick to the facts.

This technically does give them the ability to backdoor your system if they supply an "update" for something you have installed via another repo... but that is very far fetched, obvious to anyone paying attention, and would be hell for their PR for minimal gain.

Uhm....

https://en.wikipedia.org/wiki/ThreadX#cite_note-Forbes-20190...

https://en.wikipedia.org/wiki/ThreadX#Products_using_it

Post reply on HN