This is installed by adding a shady repository to your apt sources.list... How is this a supply chain attack? My official debian repository have never been breached so far. This is no different from downloading an .exe off a shady website and blindly running the .exe. Also: https://packages.debian.org/search?keywords=download+manager... lists: • uget: https://sourceforge.net/projects/urlget/ • kget: https://apps.kde.…
> This is installed by adding a shady repository to your apt sources.list... How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
Free Download Manager backdoored – a possible supply chain attack on Linux
31–40 of 143 posts
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#32This is installed by adding a shady repository to your apt sources.list... How is this a supply chain attack? My official debian repository have never been breached so far. This is no different from downloading an .exe off a shady website and blindly running the .exe. Also: https://packages.debian.org/search?keywords=download+manager... lists: • uget: https://sourceforge.net/projects/urlget/ • kget: https://apps.kde.…
> This is installed by adding a shady repository to your apt sources.list... How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
If you do it from the command line, by editing files, you will have to add the key manually.
But most inexperienced users will just copy/paste and run the "curl | sudo apt-key add" command from the shady repository website, because they want to run the software.
This is not much different from downloading an .exe from an untrusted website, and ignoring the warning from windows when running the .exe.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#33This is installed by adding a shady repository to your apt sources.list... How is this a supply chain attack? My official debian repository have never been breached so far. This is no different from downloading an .exe off a shady website and blindly running the .exe. Also: https://packages.debian.org/search?keywords=download+manager... lists: • uget: https://sourceforge.net/projects/urlget/ • kget: https://apps.kde.…
> This is installed by adding a shady repository to your apt sources.list... How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#34Earlier quoted context omitted.
> This is installed by adding a shady repository to your apt sources.list... How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
This is more like using AUR (except the packages are prebuilt with no way to inspect source). They are entirely user submitted.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#35Earlier quoted context omitted.
I disagree. This is more another reason to not run programs which are not from the official repository.
why do you think this can not happen in the official repository?
Debian packagers have a mutual trust process which you need to gain. Only trusted Debian packagers can approve packages to be included. Also some Debian maintainers will just randomly check packages from time to time. (e.g. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=792580 )
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#36But I thought there were no viruses or malware on Linux! For example: https://www.howtogeek.com/135392/htg-explains-why-you-dont-n...
Look, if the malware spreads by users manually installing it , 1. it's not really an OS problem, 2. an AV wasn't going to save them.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#37Who uses a download manager in the days of high speed internet access and, in general, cloud services?
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#38This is one more reason to run every program in a sandbox rather than with full privileges.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#39This is installed by adding a shady repository to your apt sources.list... How is this a supply chain attack? My official debian repository have never been breached so far. This is no different from downloading an .exe off a shady website and blindly running the .exe. Also: https://packages.debian.org/search?keywords=download+manager... lists: • uget: https://sourceforge.net/projects/urlget/ • kget: https://apps.kde.…
Worst is I've seen CD/CI systems which just pull unsigned unverified binaries off the internet and build software from github, random APT and YUM repos, all sorts of shit. This is then all thrown together and pushed into production systems.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#40Earlier quoted context omitted.
why do you think this can not happen in the official repository?
Because the official repository has a strict vetting process. You cannot just show up and put your shaddy software in the official repository. Debian packagers have a mutual trust process which you need to gain. Only trusted Debian packagers can approve packages to be included. Also some Debian maintainers will just randomly check packages from time to time. (e.g. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=792…
> "All we require from you is your willingness and ability to receive the funds in question"