Live data from Hacker News

OpenMandriva: Statement regarding attempted distribution sabotage

forum.openmandriva.org

31–40 of 45 posts

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#31
post #8

Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.

stop trying to make AUR sound like a place that can be compromised. it's literary a tetanus ridden landfill, by design! it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work) the fact that idiots (in the original sense of the word in Greek) made automatic installers that fool…

The arch team seems to think differently based on how they reacted to the compromise. Something doesn't have to be locked down from the start in order to be compromised.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#33
post #8

Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.

AUR has always been a risk and that wasn't the first attack of that kind. And here... Well, if it was coordinated, they would've picked a distro that doesn't prompt responses like: "Oh, mandriva still exists?"

Nah. Microsoft has better means to sell Windows.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#34

interesting that i already had blocked github.com/davidebeatrici unfortunately i did not add a note at the time

It's kind of problematic that hes part of mumble, but especially SoftEtherVPN.

Bravo, Davide, for erasing your trust score to zero. And for what? Was it worth it?

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#35

TIL Mandriva/Mandrake Linux is still around.

For the record there are at least 2 distros that carry the Mandriva/Mandrake legacy. Besides OpenMandriva there is also Mageia which I believe is the more popular option.

Related, Mageia 10 was recently released (June 30, 2026).

https://9to5linux.com/mageia-10-officially-released-with-lin...

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#36
In the Stagex Linux distribution it is not possible for any single person to release anything. We require multiple independent review and reproduction signatures from the maintainer team.

We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#37
post #21

Earlier quoted context omitted.

> How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub What's unclear? This guy was part of the project for some time and got maintainer trust. Then he brings in his mate. His mate is a crap person and gets kicked out of the project. The original guy then goes bananas and nukes stuff.

I have been part of the HN community for a while as well. I don't have admin access to its servers. That's the unclear part. How does it go from "offering to host it, which is refused" and "read-only mirror" to... this?

I understood that he was part of the team not just community. Think dang, not a random commenter. I'm pretty sure mods here have priveleges we don't.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#38
I can not evaluate the claims made, but even if I am lenient and assume it is all true, to me it is still strange how a distribution becomes so dependent on a single person or provider. I can't help but wonder how other distributions would have handled that; Gentoo would probably not have ended in a similar situation, debian probably neither.

And mind you - that's only if I evaluate the claims made at face value. I also can't help but feel that there are some missing steps here. Sure, IRC roid-raging happened in the past, see #freenode, and people are strange in general, but even then it really reads oddly to me, almost as if "I trusted that scammer from Nigeria with my money because the emails were so convincing".

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#39

Earlier quoted context omitted.

stop trying to make AUR sound like a place that can be compromised. it's literary a tetanus ridden landfill, by design! it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work) the fact that idiots (in the original sense of the word in Greek) made automatic installers that fool…

The arch team seems to think differently based on how they reacted to the compromise. Something doesn't have to be locked down from the start in order to be compromised.

Not being willing to knowingly and actively distribute malware does not mean they don't agree with OP. All the "use at own risk, no vetting" warnings all over the AUR and wiki support OPs claim if anything.

Re: OpenMandriva: Statement regarding attempted distribution sabotage

#40
post #8

Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.

>feel like there's some organized attempt to paint Linux distros as dangerous.

imo the only ones doing that are the ones that try to portray the AUR as more than it actually is. A pastebin for package builds with "run at your own risk" all over it. It would be more concerning if there wasn't anything malicious found ever other day.

Post reply on HN