Live data from Hacker News

You might want to stop running atop

rachelbythebay.com

51–60 of 155 posts

Re: You might want to stop running atop

#51
post #37
post #21

Probably a backdoor. Repositories controlled by accounts based in mainland China and Russia are always a risk- it's too easy for a dictatorship to force something to happen even if the authors themselves are trying to act in good faith. XZ, Swoole... examples off the top of my head.

What about the fact that software is hosted on US/German/Australian/whatever else platforms and infrastructure, what's different with that, technically speaking? The fact that a majority of software we rely on is hosted on GitHub, isn't that scary the same way that a repo owned by someone in a other country is scary? Does a government need to openly act in a specific way for there to be a risk, or is this perceived r…

GitHub has a lot to lose if it was leaked that they were knowingly facilitating backdoors behind the scenes- many pay for the convenience and trust.

By the same standard, what are the repercussions for these random fly by night accounts? Just make a new account and try again on an existing project or fork / tweak / rebrand another project.

Steam, VSCode, PyPI, NPM... it would ruin those platforms overnight if they were putting in backdoors themselves.

Re: You might want to stop running atop

#52
post #37
post #21

Probably a backdoor. Repositories controlled by accounts based in mainland China and Russia are always a risk- it's too easy for a dictatorship to force something to happen even if the authors themselves are trying to act in good faith. XZ, Swoole... examples off the top of my head.

What about the fact that software is hosted on US/German/Australian/whatever else platforms and infrastructure, what's different with that, technically speaking? The fact that a majority of software we rely on is hosted on GitHub, isn't that scary the same way that a repo owned by someone in a other country is scary? Does a government need to openly act in a specific way for there to be a risk, or is this perceived r…

These are all good questions where the answer is usually something along the lines of solving them with reproducible builds and Nix, which sounds good until someone points out where the Nix ecosystem gets its funding.

Re: You might want to stop running atop

#53
post #46

Is atop included in any distributions? Is there even a tool to search what is pre-installed in each major distribution(s)?

"Ubuntu, Debian, Red Hat Enterprise Linux, Fedora, Linux Mint, SUSE Linux Enterprise, CentOS, Manjaro, elementary OS, Gentoo, Oracle Linux, and Pop!_OS" ~--Google's AI.

I am not aware of any that install it by default.

Re: You might want to stop running atop

#54
post #11

This screams NDA/disclosure but things are so mega super fucked that they feel obligated to pre warn as early as possible. I wonder how long/old the problem is in atop?

Yeah, from a rando this would be just bad vagueposting but Rachel is absolutely someone who could know about a very good reason why we should uninstall atop but be unable to legally say why. I would heed her warning.

I would disagree and still say that this is bad vagueposting. It doesn't matter how reputable the source is: if you say "don't do X" but don't give a reason why, I'm not inclined to listen. Granted I don't use atop anyways, but I don't think a vague blog post - even one from a respected person - is sufficient justification to change what software one uses.

Re: You might want to stop running atop

#55
post #51
post #37

Earlier quoted context omitted.

What about the fact that software is hosted on US/German/Australian/whatever else platforms and infrastructure, what's different with that, technically speaking? The fact that a majority of software we rely on is hosted on GitHub, isn't that scary the same way that a repo owned by someone in a other country is scary? Does a government need to openly act in a specific way for there to be a risk, or is this perceived r…

GitHub has a lot to lose if it was leaked that they were knowingly facilitating backdoors behind the scenes- many pay for the convenience and trust. By the same standard, what are the repercussions for these random fly by night accounts? Just make a new account and try again on an existing project or fork / tweak / rebrand another project. Steam, VSCode, PyPI, NPM... it would ruin those platforms overnight if they we…

Reputational loss isn't a good argument either, because what the comment I replied to said is that repositories in control of people in e.g. Russia are dangerous. That implies that a Russian or Chinese maintainer of popular open source software is not safe, whereas someone employed by an American company is.

However, maintainers have a reputational loss risk, just like someone working at a company does, no?

And, of course, GitHub could just replace the file you're served when you download a file from it, and then blame a hacker, a rogue employee, or deny it happened. That is just as well technically possible as any other entity being forced, by their government, to do something, no?

And, of course, if a govt forces you, your reputation is not the thing you're worried about.

I understand your argument, but that seems like it's a different argument from the one I was disagreeing with.

Re: You might want to stop running atop

#59
post #32

Earlier quoted context omitted.

Why would there be an NDA on atop? It's under GPL.

It might be covered under an NDA with some company that she's contracting with if she/they discovered the vulnerability in the course of their work.

"screams NDA" is not the same as "might be covered under an NDA". And in any case, very likely the said company has already taken mitigative action like removing atop already.

Re: You might want to stop running atop

#60
post #21

Probably a backdoor. Repositories controlled by accounts based in mainland China and Russia are always a risk- it's too easy for a dictatorship to force something to happen even if the authors themselves are trying to act in good faith. XZ, Swoole... examples off the top of my head.

> it's too easy for a dictatorship to force something

We really need to get rid of this mentality. Australia has laws that allow undisclosed, compelled, software updates. Verbally by ministers, but written (confidential) changes can be requested by federal agencies. Many western countries have followed to various degrees. There's no stable trusted government that doesn't want its fingers in your code.

Post reply on HN