Free Download Manager backdoored – a possible supply chain attack on Linux
1–10 of 143 posts
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#2Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#3Who uses a download manager in the days of high speed internet access and, in general, cloud services?
I mean if I found something called free download manager on a technologically challenged family member's PC I would just assume its malware to start with.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#4Who uses a download manager in the days of high speed internet access and, in general, cloud services?
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#5Who uses a download manager in the days of high speed internet access and, in general, cloud services?
I'm trying to imagine the kind of user that's both able to blindly install a random .deb downloaded from a website, while also being willing to do so. Linux geeks with no sense of danger on the internet?
Couple that with the fact that it works out well Most Of The Time[0] and you've got a pretty likely scenario even if it affects a relatively small number of people.
[0] I mean in general when downloading software as well as in the context of this particular story[1].
[1] > Starting in 2020, the same domain at times redirected users to the domain deb.fdmpkg[.]org, which served a malicious version of the app.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#6Submitters: "Please submit the original source. If a post reports on something found on another site, submit the latter." - https://news.ycombinator.com/newsguidelines.html
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#7Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#8Who uses a download manager in the days of high speed internet access and, in general, cloud services?
On linux... I mean if I found something called free download manager on a technologically challenged family member's PC I would just assume its malware to start with.
Logitech did similar hijinks for a long time. I can't remember whether it was mandatory, but it sure was difficult to avoid.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#9Who uses a download manager in the days of high speed internet access and, in general, cloud services?