Live data from Hacker News

OpenMandriva: Statement regarding attempted distribution sabotage

forum.openmandriva.org

11–20 of 45 posts

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#11
post #2

How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."? I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonabl…

> How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub

What's unclear? This guy was part of the project for some time and got maintainer trust. Then he brings in his mate. His mate is a crap person and gets kicked out of the project. The original guy then goes bananas and nukes stuff.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#12
post #8

Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.

i mean, they're succeeding. whether it's coordinated or not the conclusion is the same.

but i think "linux distributions are dangerous" is the wrong conclusion. the right one is to treat each distribution based on their own security practices, and not "linux" as a whole. one distro's bad practices doesn't make others unsafe any more than one distribution's good practices make other safe.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#14
post #8

Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.

i mean, they're succeeding. whether it's coordinated or not the conclusion is the same. but i think "linux distributions are dangerous" is the wrong conclusion. the right one is to treat each distribution based on their own security practices, and not "linux" as a whole. one distro's bad practices doesn't make others unsafe any more than one distribution's good practices make other safe.

The real takeaway for projects and companies should be that someone having historically behaved in a logical and responsible way doesn’t guarantee that they’ll continue to do that for forever.

Good security architecture has circuit breakers, even for people who are generally high-trust.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#15
I feel for the maintaners. There is a push and pull here on OSS.

However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam.

Because Im not dependent on PRs from randos this doesnt really matter to me. I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host.

And go underground. Or decide whether the juice is any longer worth the squeeze. In my mind its not unless its off the internet. You may skate today, tomorrow you are completely screwed.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#16
post #2

How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."? I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonabl…

It's hard to maintain open source software that needs infrastructure. Everyone is a volunteer and it's not like the Mandriva project has the resources to fully vet people as well as have a high quality RBAC and access control system. This guy sounds like maintained a large project, offered to help, and Mandriva saw the Trojan horse as a way to alleviate a lot of their problems. And it didn't sound like he was able to…

> It just sounds like the Mandriva maintainers are trusting and good folk who may be overworked running an open source project and that led to a bad apple entering the bunch. It's hard for me to be mad in that kind of situation.

It's hard to be mad, but people in FLOSS need to start taking this sort of cautionary tale to heart, particularly when it comes to Linux distros.

If you don't have a good way to sustain maintenance and development of a software project in the current era - one with LLM spam, social engineering, and apparently, jackass contributors - you need to start looking into ways to wrap the project up and focus your energies on more established projects that might need help.

I know that sounds mean, but this isn't just a hobby project anymore. This is an operating system. People put their entire lives on their computers. It's not a failure, you can do everything right and end up in a situation like we see here.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#17
post #8

Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.

I wouldn't say that there's an organized attempt to "paint Linux distros as dangerous". It's just what happens when you have people being people (as we see here) and there are structural vulnerabilities to software supply chains.

It's a juicy target, and it's being exploited. We can either learn from it or continue to suffer.

This isn't even new. Hell, I remember when Linux Mint was hacked a decade or more ago. They compromised the forums, the disk image downloads, the whole shebang. I haven't used it since.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#18

I feel for the maintaners. There is a push and pull here on OSS. However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam. Because Im not dependent on PRs from randos this doesnt really matter to me. I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host. And go underground. Or decide whether…

Slop PRs are just spam, we learned to deal with spam on email, we'll learn to deal with this as well.

Fwiw, I don't think it's an "AI" problem, is a knowledge and respect problem from the people that have their agents dump code on FOSS projects.

Post reply on HN