Live data from Hacker News

I found 10k GitHub repositories distributing Trojan malware

orchidfiles.com

41–50 of 268 posts

Re: I found 10k GitHub repositories distributing Trojan malware

#41

Earlier quoted context omitted.

> the principle that open-source software can't do anything nefarious because the source is open just hasn't held up for a lot of reasons You've been living on such a principle? That sounds insane, why would something not be nefarious just because you can read the code? The way I was "raised" by FOSS greybeards screaming at me through web forums, was that any software available on 3rd party websites anyone can upload…

> You've been living on such a principle? I have not, but in case you missed it, this principle has been used by open source proponents for decades. I'm an open source developer myself, but always found it odd.

No, it's really not, and really hasn't been. Do people truly have such poor reasoning and logic skills?

"Closed source software is inscrutable, impossible for me to fix, impossible for me to review the source" is absolutely a distinct statement from "it is impossible to hide malware in open-source software". I've literally never heard someone claim the latter.

(edit for coherency, thanks graemep)

Re: I found 10k GitHub repositories distributing Trojan malware

#42
post #30

Earlier quoted context omitted.

Pretty happy with having a yubikey on my keychain. Log in someplace new? plonk in your yubikey and off you go!

I used to keep a yubikey in a spare slot on my laptop. One day it fell out and subsequently escaped through an unnoticed hole in my backpack. I've never lost a password because my backpack was overly abused.

That's why you keep it on your keychain and not in a spare slot on your laptop.

Re: I found 10k GitHub repositories distributing Trojan malware

#43
post #30

Earlier quoted context omitted.

Pretty happy with having a yubikey on my keychain. Log in someplace new? plonk in your yubikey and off you go!

And when your keychain gets lost then what?

I open the safe where I keep my spare Yubikey. Or I use the passkey stored in my phone, or the one on my laptop. Make passkeys, put them everywhere.

Re: I found 10k GitHub repositories distributing Trojan malware

#44
post #30

Earlier quoted context omitted.

Pretty happy with having a yubikey on my keychain. Log in someplace new? plonk in your yubikey and off you go!

And when your keychain gets lost then what?

Then I have a backup yubikey at home for services which allow to register two keys. For other's there's still good old password+some second factor.

Re: I found 10k GitHub repositories distributing Trojan malware

#45

I have to say, the principle that open-source software can't do anything nefarious because the source is open just hasn't held up for a lot of reasons -- including that nobody has the time to inspect the code, let alone ensure that it matches the binaries; and also that GitHub has become a distribution hub for software used by lots of people with no ability or interest in auditing the software they use.

The choice is between code you can validate and code you can't, not code that has malware and code that doesn't.

Re: I found 10k GitHub repositories distributing Trojan malware

#46

Earlier quoted context omitted.

> the principle that open-source software can't do anything nefarious because the source is open just hasn't held up for a lot of reasons You've been living on such a principle? That sounds insane, why would something not be nefarious just because you can read the code? The way I was "raised" by FOSS greybeards screaming at me through web forums, was that any software available on 3rd party websites anyone can upload…

No, I've not been "living on" such a principle but it was a big claim for "the bazaar."

You'd better read it again, because that claim does not figure in that text. You might mean that with more eyes on the code, more bugs are found, than with no eyes on the code. But that is not what you are saying here.

Re: I found 10k GitHub repositories distributing Trojan malware

#47

> I typed the project name into Google, and my repository appeared in the results. I entered the same query into Bing, and someone else’s repository appeared in the results Side story, this kind of thing is what made me stop using Bing. I had been using it as the default for searches (it sucks, but it's at least not Google), until I landed on a phishing page for my bank (I haven't committed it to memory yet). The pag…

Why would you go to your bank by first searching for it? Sounds very insecure to me. I type my banks url directly instead, or if that gets tedious, store it as a bookmark.

I know several people who search for important sites, click uncritically on links, and get scammed. This is not so good.

Re: I found 10k GitHub repositories distributing Trojan malware

#48

> I typed the project name into Google, and my repository appeared in the results. I entered the same query into Bing, and someone else’s repository appeared in the results Side story, this kind of thing is what made me stop using Bing. I had been using it as the default for searches (it sucks, but it's at least not Google), until I landed on a phishing page for my bank (I haven't committed it to memory yet). The pag…

    at least not Google
Is one giant mega-corp better than any other?

You're going to have a hard time convincing me the answer is yes.

Re: I found 10k GitHub repositories distributing Trojan malware

#49

I have to say, the principle that open-source software can't do anything nefarious because the source is open just hasn't held up for a lot of reasons -- including that nobody has the time to inspect the code, let alone ensure that it matches the binaries; and also that GitHub has become a distribution hub for software used by lots of people with no ability or interest in auditing the software they use.

[deleted]

Re: I found 10k GitHub repositories distributing Trojan malware

#50

Earlier quoted context omitted.

> You've been living on such a principle? I have not, but in case you missed it, this principle has been used by open source proponents for decades. I'm an open source developer myself, but always found it odd.

No, it's really not, and really hasn't been. Do people truly have such poor reasoning and logic skills? "Closed source software is inscrutable, impossible for me to fix, impossible for me to review the source" is absolutely a distinct statement from "it is impossible to hide malware in open-source software". I've literally never heard someone claim the latter. (edit for coherency, thanks graemep)

I think you mean open source in the second bit in quotes.
Post reply on HN