Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.
stop trying to make AUR sound like a place that can be compromised. it's literary a tetanus ridden landfill, by design! it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work) the fact that idiots (in the original sense of the word in Greek) made automatic installers that fool…
OpenMandriva: Statement regarding attempted distribution sabotage
31–40 of 45 posts
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#32"should have" "could have". Geez. This was malicious. Take legal action already!
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#33Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.
Nah. Microsoft has better means to sell Windows.
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#34interesting that i already had blocked github.com/davidebeatrici unfortunately i did not add a note at the time
Bravo, Davide, for erasing your trust score to zero. And for what? Was it worth it?
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#35TIL Mandriva/Mandrake Linux is still around.
For the record there are at least 2 distros that carry the Mandriva/Mandrake legacy. Besides OpenMandriva there is also Mageia which I believe is the more popular option.
https://9to5linux.com/mageia-10-officially-released-with-lin...
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#36We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#37Earlier quoted context omitted.
> How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub What's unclear? This guy was part of the project for some time and got maintainer trust. Then he brings in his mate. His mate is a crap person and gets kicked out of the project. The original guy then goes bananas and nukes stuff.
I have been part of the HN community for a while as well. I don't have admin access to its servers. That's the unclear part. How does it go from "offering to host it, which is refused" and "read-only mirror" to... this?
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#38And mind you - that's only if I evaluate the claims made at face value. I also can't help but feel that there are some missing steps here. Sure, IRC roid-raging happened in the past, see #freenode, and people are strange in general, but even then it really reads oddly to me, almost as if "I trusted that scammer from Nigeria with my money because the emails were so convincing".
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#39Earlier quoted context omitted.
stop trying to make AUR sound like a place that can be compromised. it's literary a tetanus ridden landfill, by design! it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work) the fact that idiots (in the original sense of the word in Greek) made automatic installers that fool…
The arch team seems to think differently based on how they reacted to the compromise. Something doesn't have to be locked down from the start in order to be compromised.
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#40Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.
imo the only ones doing that are the ones that try to portray the AUR as more than it actually is. A pastebin for package builds with "run at your own risk" all over it. It would be more concerning if there wasn't anything malicious found ever other day.