Raspberry Pi OS comes with a ton of stuff, among others, Minecraft or the "Pi Store". It is not a minimal building block for your custom hacked Linux firmware, it's what they provide so teachers can install the stuff and have kids use it without going to a console and editing sources.list first.
Microsoft repo installed on all Raspberry Pi’s
21–30 of 30 posts
Re: Microsoft repo installed on all Raspberry Pi’s
#22Earlier quoted context omitted.
But this doesn't grant remote access to your system, and it's not like Microsoft will start shipping replacements of core packages over this repo.
Technically it does grant another avenue of supply chain attack... but if Microsoft run mirrors are being compromised then we probably have much bigger issues than some raspberry pis.
Re: Microsoft repo installed on all Raspberry Pi’s
#23Redmond got finally a root shell on your Pi :-)
This is not even remotely true. All they have is the information that somene at $IP is using Rpi. Granted, I'd prefer not to give them this info, but let's stick to the facts.
So yes, in fact, it's quite true.
Re: Microsoft repo installed on all Raspberry Pi’s
#24Re: Microsoft repo installed on all Raspberry Pi’s
#25This feels like a huge overreaction. "(...) every time an install of Raspberry Pi OS is updated it will ping a Microsoft server. Microsoft will know you're using Raspberry Pi OS/likely Raspberry Pi owner and your IP address." How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. I imagine that Raspberry Pi OS is an distro meant for people who simply want things…
> How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. Yes, but it's you who usually manage those mirrors, not some guy deciding which mirrors your apt must query now and pushing it in a regular update without notice. I don't care if it's Microsoft or some obscure Chinese repo, but I think nobody should mess with your mirrors list or trust their keys in this wa…
Re: Microsoft repo installed on all Raspberry Pi’s
#26This feels like a huge overreaction. "(...) every time an install of Raspberry Pi OS is updated it will ping a Microsoft server. Microsoft will know you're using Raspberry Pi OS/likely Raspberry Pi owner and your IP address." How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. I imagine that Raspberry Pi OS is an distro meant for people who simply want things…
> How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. Yes, but it's you who usually manage those mirrors, not some guy deciding which mirrors your apt must query now and pushing it in a regular update without notice. I don't care if it's Microsoft or some obscure Chinese repo, but I think nobody should mess with your mirrors list or trust their keys in this wa…
That's not true for most people.
Re: Microsoft repo installed on all Raspberry Pi’s
#27To put this into perspective, I'd like to kbow how many repos and gpg keys are there already. If microsoft was added to dozens others, then this is a storm in a teacup. If it when from 2 to 3, then the change is more significant. Lets keep in mind that the central goal of PI OS is education, not security, privacy, sticking it to corporates, IoT, etc.
Raspberry Pi has many product lines for industrial and IOT usage, including the Compute Module where security and privacy are expected. The standard operating system for such systems tends to be Raspbian Lite now called (Raspberry Pi OS Lite), which is affected by this issue.
There is no real iot-style security in Raspbian lite, so before you get mad pver microsoft eepo being added, toy should be sorting that out
Re: Microsoft repo installed on all Raspberry Pi’s
#28Earlier quoted context omitted.
> How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror. Yes, but it's you who usually manage those mirrors, not some guy deciding which mirrors your apt must query now and pushing it in a regular update without notice. I don't care if it's Microsoft or some obscure Chinese repo, but I think nobody should mess with your mirrors list or trust their keys in this wa…
If you don't want "some guy" deciding which APT mirrors you use, then don't use "some guy's" linux distribution
Re: Microsoft repo installed on all Raspberry Pi’s
#29Earlier quoted context omitted.
Raspberry Pi has many product lines for industrial and IOT usage, including the Compute Module where security and privacy are expected. The standard operating system for such systems tends to be Raspbian Lite now called (Raspberry Pi OS Lite), which is affected by this issue.
I think that if you are producing a real device based on a compute module, you should not be using Rasbian Lite, things like Arch, Ubunti core, etc. are more suited for the purpose. There is no real iot-style security in Raspbian lite, so before you get mad pver microsoft eepo being added, toy should be sorting that out
Debian is a reasonably platform for such devices (though not the best due to the ~2 year release cycles, rather than eg, 10 years for CentOS distributions back when they were around). I do take the point that Ubuntu Core may be even more suitable, but Raspbian should work fine for many real world applications.
Re: Microsoft repo installed on all Raspberry Pi’s
#30Earlier quoted context omitted.
This is not even remotely true. All they have is the information that somene at $IP is using Rpi. Granted, I'd prefer not to give them this info, but let's stick to the facts.
This technically does give them the ability to backdoor your system if they supply an "update" for something you have installed via another repo... but that is very far fetched, obvious to anyone paying attention, and would be hell for their PR for minimal gain.