OpenMandriva: Statement regarding attempted distribution sabotage(forum.openmandriva.org) |
OpenMandriva: Statement regarding attempted distribution sabotage(forum.openmandriva.org) |
I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonably well-known, but in the post it doesn't sound like he was a core maintainer, or even a very active community member. Do they just randomly hand out admin access to anyone?
And it didn't sound like he was able to "nuke everything" - it sounds like he had access to their repository infrastructure (which is reasonable given he was volunteering to host it) and then lashed out.
If anything, I think it's a bigger organizational red flag that they agreed to privately host their source code on some random git forge and not a larger, more communal one. I mean, even if they didn't want to use GitHub (did this even cost money for them) then there are other providers to choose from.
It just sounds like the Mandriva maintainers are trusting and good folk who may be overworked running an open source project and that led to a bad apple entering the bunch. It's hard for me to be mad in that kind of situation.
I don't think that categorization is warranted - at least the linked announcement doesn't give any indication that the guy joined with the intent to cause trouble and its only after his friend got in trouble that he misused the access he had. No amount of vetting can prevent something like that entirely and only disconnected backups (thanks, git) will help you in the end.
> If anything, I think it's a bigger organizational red flag that they agreed to privately host their source code on some random git forge and not a larger, more communal one.
Did they agree to it? The linked post only says that it was offered and being discussed.
> even if they didn't want to use GitHub (did this even cost money for them)
Money is hardly the only reason why an open source project could have a problem with using GitHub.
The post makes zero mention of him ever joining or being part of the core infra ops team. So where did the admin access come from?
It's hard to be mad, but people in FLOSS need to start taking this sort of cautionary tale to heart, particularly when it comes to Linux distros.
If you don't have a good way to sustain maintenance and development of a software project in the current era - one with LLM spam, social engineering, and apparently, jackass contributors - you need to start looking into ways to wrap the project up and focus your energies on more established projects that might need help.
I know that sounds mean, but this isn't just a hobby project anymore. This is an operating system. People put their entire lives on their computers. It's not a failure, you can do everything right and end up in a situation like we see here.
What's unclear? This guy was part of the project for some time and got maintainer trust. Then he brings in his mate. His mate is a crap person and gets kicked out of the project. The original guy then goes bananas and nukes stuff.
I'm so glad the project is still around.
https://9to5linux.com/mageia-10-officially-released-with-lin...
It's a juicy target, and it's being exploited. We can either learn from it or continue to suffer.
This isn't even new. Hell, I remember when Linux Mint was hacked a decade or more ago. They compromised the forums, the disk image downloads, the whole shebang. I haven't used it since.
We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.
And mind you - that's only if I evaluate the claims made at face value. I also can't help but feel that there are some missing steps here. Sure, IRC roid-raging happened in the past, see #freenode, and people are strange in general, but even then it really reads oddly to me, almost as if "I trusted that scammer from Nigeria with my money because the emails were so convincing".
However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam.
Because Im not dependent on PRs from randos this doesnt really matter to me. I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host.
And go underground. Or decide whether the juice is any longer worth the squeeze. In my mind its not unless its off the internet. You may skate today, tomorrow you are completely screwed.
Fwiw, I don't think it's an "AI" problem, is a knowledge and respect problem from the people that have their agents dump code on FOSS projects.
Every time someone actively approaches you with an offer to spend their real energy and lifetime on your thing, It's almost always about leverage in some way.
At least if there is actual work attached to it.
Money alone might be paid by people that just have too much of it or want to feel better about something.
But if they actively involve themselves to a degree that goes way beyond scratching their own itch, something's up.
You might get lucky and find a just genuinely good person, but you might also not.
https://forum.openmandriva.org/t/statement-regarding-attempt...
Shameful.
unfortunately i did not add a note at the time
Bravo, Davide, for erasing your trust score to zero. And for what? Was it worth it?
Nah. Microsoft has better means to sell Windows.
imo the only ones doing that are the ones that try to portray the AUR as more than it actually is. A pastebin for package builds with "run at your own risk" all over it. It would be more concerning if there wasn't anything malicious found ever other day.
but i think "linux distributions are dangerous" is the wrong conclusion. the right one is to treat each distribution based on their own security practices, and not "linux" as a whole. one distro's bad practices doesn't make others unsafe any more than one distribution's good practices make other safe.
Good security architecture has circuit breakers, even for people who are generally high-trust.
it's literary a tetanus ridden landfill, by design!
it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work)
the fact that idiots (in the original sense of the word in Greek) made automatic installers that fools novices to think those are vetted distro packages doesn't make it so.
But then, temporary become permanent because either the task never complete or because people just forgot. It's always when the problems start to appear that the temporary privileges are finally revoked.
In my case the problems were mostly due to incompetence, but sometimes a malicious action happens...
It's not the 00s anymore. You are not special if you can post code that compiles to a central repository where people can duplicate and modify it. There are entire colleges in most developed nations that have 18-year-olds who can do the same thing now. The key to being taken seriously is figuring out how to do that sustainably and responsibly.