How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."? I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonabl…
> How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub What's unclear? This guy was part of the project for some time and got maintainer trust. Then he brings in his mate. His mate is a crap person and gets kicked out of the project. The original guy then goes bananas and nukes stuff.
OpenMandriva: Statement regarding attempted distribution sabotage
21–30 of 45 posts
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#22How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."? I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonabl…
It's hard to maintain open source software that needs infrastructure. Everyone is a volunteer and it's not like the Mandriva project has the resources to fully vet people as well as have a high quality RBAC and access control system. This guy sounds like maintained a large project, offered to help, and Mandriva saw the Trojan horse as a way to alleviate a lot of their problems. And it didn't sound like he was able to…
The post makes zero mention of him ever joining or being part of the core infra ops team. So where did the admin access come from?
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#23Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.
it's literary a tetanus ridden landfill, by design!
it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work)
the fact that idiots (in the original sense of the word in Greek) made automatic installers that fools novices to think those are vetted distro packages doesn't make it so.
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#24Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#25How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."? I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonabl…
It's hard to maintain open source software that needs infrastructure. Everyone is a volunteer and it's not like the Mandriva project has the resources to fully vet people as well as have a high quality RBAC and access control system. This guy sounds like maintained a large project, offered to help, and Mandriva saw the Trojan horse as a way to alleviate a lot of their problems. And it didn't sound like he was able to…
I don't think that categorization is warranted - at least the linked announcement doesn't give any indication that the guy joined with the intent to cause trouble and its only after his friend got in trouble that he misused the access he had. No amount of vetting can prevent something like that entirely and only disconnected backups (thanks, git) will help you in the end.
> If anything, I think it's a bigger organizational red flag that they agreed to privately host their source code on some random git forge and not a larger, more communal one.
Did they agree to it? The linked post only says that it was offered and being discussed.
> even if they didn't want to use GitHub (did this even cost money for them)
Money is hardly the only reason why an open source project could have a problem with using GitHub.
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#26TIL Mandriva/Mandrake Linux is still around.
Me too. It was my first Linux back in 2003 and I was immediately hooked. Back then codecs weren't as much of an issue as they were in the late 2000s to early 2010s so everything worked out of the box and the performance on Pentium 4 with 128 MB RAM was phenomenal compared to Windows XP. I'm so glad the project is still around.
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#27Earlier quoted context omitted.
It's hard to maintain open source software that needs infrastructure. Everyone is a volunteer and it's not like the Mandriva project has the resources to fully vet people as well as have a high quality RBAC and access control system. This guy sounds like maintained a large project, offered to help, and Mandriva saw the Trojan horse as a way to alleviate a lot of their problems. And it didn't sound like he was able to…
> It just sounds like the Mandriva maintainers are trusting and good folk who may be overworked running an open source project and that led to a bad apple entering the bunch. It's hard for me to be mad in that kind of situation. It's hard to be mad, but people in FLOSS need to start taking this sort of cautionary tale to heart, particularly when it comes to Linux distros. If you don't have a good way to sustain maint…
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#28Earlier quoted context omitted.
It's hard to maintain open source software that needs infrastructure. Everyone is a volunteer and it's not like the Mandriva project has the resources to fully vet people as well as have a high quality RBAC and access control system. This guy sounds like maintained a large project, offered to help, and Mandriva saw the Trojan horse as a way to alleviate a lot of their problems. And it didn't sound like he was able to…
That's the thing: according to the post he offered it, but the offer wasn't accepted. They stayed on Github, and it was the Github repos which were compromised. They did entertain his desire to let him host a read-only mirror - but that's hardly critical, and having complete strangers mirroring Linux ISOs or package repos has been a thing for ages. The post makes zero mention of him ever joining or being part of the…
But then, temporary become permanent because either the task never complete or because people just forgot. It's always when the problems start to appear that the temporary privileges are finally revoked.
In my case the problems were mostly due to incompetence, but sometimes a malicious action happens...
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#29Earlier quoted context omitted.
> How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub What's unclear? This guy was part of the project for some time and got maintainer trust. Then he brings in his mate. His mate is a crap person and gets kicked out of the project. The original guy then goes bananas and nukes stuff.
I have been part of the HN community for a while as well. I don't have admin access to its servers. That's the unclear part. How does it go from "offering to host it, which is refused" and "read-only mirror" to... this?
Re: OpenMandriva: Statement regarding attempted distribution sabotage
#30I feel for the maintaners. There is a push and pull here on OSS. However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam. Because Im not dependent on PRs from randos this doesnt really matter to me. I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host. And go underground. Or decide whether…
Slop PRs are just spam, we learned to deal with spam on email, we'll learn to deal with this as well. Fwiw, I don't think it's an "AI" problem, is a knowledge and respect problem from the people that have their agents dump code on FOSS projects.