Live data from Hacker News

Free Download Manager backdoored – a possible supply chain attack on Linux

securelist.com

1–10 of 143 posts

Re: Free Download Manager backdoored – a possible supply chain attack on Linux

#3
post #2

Who uses a download manager in the days of high speed internet access and, in general, cloud services?

On linux...

I mean if I found something called free download manager on a technologically challenged family member's PC I would just assume its malware to start with.

Re: Free Download Manager backdoored – a possible supply chain attack on Linux

#4
post #2

Who uses a download manager in the days of high speed internet access and, in general, cloud services?

I'm trying to imagine the kind of user that's both able to blindly install a random .deb downloaded from a website, while also being willing to do so. Linux geeks with no sense of danger on the internet?

Re: Free Download Manager backdoored – a possible supply chain attack on Linux

#5
post #4
post #2

Who uses a download manager in the days of high speed internet access and, in general, cloud services?

I'm trying to imagine the kind of user that's both able to blindly install a random .deb downloaded from a website, while also being willing to do so. Linux geeks with no sense of danger on the internet?

One can google "install .deb fedora" and get a litany of web pages which will contain words explaining how to do this. Fedora (and other distributions) is easy enough to install that one doesn't really need to be a "Linux geek" in order to be on Linux and such a person is not quite so likely to wonder whether or not they trust the code they're running.

Couple that with the fact that it works out well Most Of The Time[0] and you've got a pretty likely scenario even if it affects a relatively small number of people.

[0] I mean in general when downloading software as well as in the context of this particular story[1].

[1] > Starting in 2020, the same domain at times redirected users to the domain deb.fdmpkg[.]org, which served a malicious version of the app.

Re: Free Download Manager backdoored – a possible supply chain attack on Linux

#6
Url changed from https://arstechnica.com/security/2023/09/password-stealing-l..., which points to this.

Submitters: "Please submit the original source. If a post reports on something found on another site, submit the latter." - https://news.ycombinator.com/newsguidelines.html

Re: Free Download Manager backdoored – a possible supply chain attack on Linux

#8
post #3
post #2

Who uses a download manager in the days of high speed internet access and, in general, cloud services?

On linux... I mean if I found something called free download manager on a technologically challenged family member's PC I would just assume its malware to start with.

Honestly, there were several download managers which were essentially forced by folks like Microsoft and Logitech. If I remember correctly, when I had an educational license with Microsoft Imagine, the most challenging bit was getting the mandatory download manager working. IIRC, I didn't actually have a Windows machine to put it on or something. So, I had to jump through some hoops. The software was plain inaccessible without going through the proprietary download manager.

Logitech did similar hijinks for a long time. I can't remember whether it was mandatory, but it sure was difficult to avoid.

Re: Free Download Manager backdoored – a possible supply chain attack on Linux

#9
post #2

Who uses a download manager in the days of high speed internet access and, in general, cloud services?

I do. Just because your internet access is fast that doesn't mean remote servers don't throttle on a per connection basis.

Re: Free Download Manager backdoored – a possible supply chain attack on Linux

#10
post #9
post #2

Who uses a download manager in the days of high speed internet access and, in general, cloud services?

I do. Just because your internet access is fast that doesn't mean remote servers don't throttle on a per connection basis.

Or that everyone else also has fast Internet
Post reply on HN