Live data from Hacker News

You might want to stop running atop

rachelbythebay.com

31–40 of 155 posts

Re: You might want to stop running atop

#31
post #28

I’m actually surprised I didn’t have it installed, what with all the packages I check out just through sheer curiosity. Thanks Rachel! I’ll avoid it in the future.

Alarmingly, I had it installed on my home server, for some odd reason. I don't remember ever using it.

Same here. I installed, and I don't remember why, and I've never once used it.

Re: You might want to stop running atop

#34
post #32
post #11

This screams NDA/disclosure but things are so mega super fucked that they feel obligated to pre warn as early as possible. I wonder how long/old the problem is in atop?

Why would there be an NDA on atop? It's under GPL.

It might be covered under an NDA with some company that she's contracting with if she/they discovered the vulnerability in the course of their work.

Re: You might want to stop running atop

#35
post #33

Luckily I use a much better *top, btop.

This. Not only that, I don't know of a single person (IRL or online) who used atop, like, ever. In fact, this is the first time I'm even hearing of atop.

IIRC, most folks went from top -> htop -> glances -> various btop variants (bashtop, bpytop, btop++ etc)

Re: You might want to stop running atop

#37
post #21

Probably a backdoor. Repositories controlled by accounts based in mainland China and Russia are always a risk- it's too easy for a dictatorship to force something to happen even if the authors themselves are trying to act in good faith. XZ, Swoole... examples off the top of my head.

What about the fact that software is hosted on US/German/Australian/whatever else platforms and infrastructure, what's different with that, technically speaking? The fact that a majority of software we rely on is hosted on GitHub, isn't that scary the same way that a repo owned by someone in a other country is scary?

Does a government need to openly act in a specific way for there to be a risk, or is this perceived risk due to a media bias?

I'm genuinely curious if there's a good answer

Re: You might want to stop running atop

#38
post #35
post #33

Luckily I use a much better *top, btop.

This. Not only that, I don't know of a single person (IRL or online) who used atop, like, ever. In fact, this is the first time I'm even hearing of atop. IIRC, most folks went from top -> htop -> glances -> various btop variants (bashtop, bpytop, btop++ etc)

Btop variants, glances, why should I move from htop?

Re: You might want to stop running atop

#39
post #32

Earlier quoted context omitted.

Why would there be an NDA on atop? It's under GPL.

It might be covered under an NDA with some company that she's contracting with if she/they discovered the vulnerability in the course of their work.

It could also be any number of other things too, like it's severe enough that the author feels its responsible to wait for mitigation efforts before disclosing anything about the issue that could lead to it being exploited.

Re: You might want to stop running atop

#40
post #37
post #21

Probably a backdoor. Repositories controlled by accounts based in mainland China and Russia are always a risk- it's too easy for a dictatorship to force something to happen even if the authors themselves are trying to act in good faith. XZ, Swoole... examples off the top of my head.

What about the fact that software is hosted on US/German/Australian/whatever else platforms and infrastructure, what's different with that, technically speaking? The fact that a majority of software we rely on is hosted on GitHub, isn't that scary the same way that a repo owned by someone in a other country is scary? Does a government need to openly act in a specific way for there to be a risk, or is this perceived r…

[deleted]
Post reply on HN