2 ms·
I'm far from an expert, but my guess is that the quote > "Windows provides multiple ways to do it," he said. But DLL hijacking isn't limited to Windows, he sai
by EnFinlay 9y ago
I'm far from an expert, but my guess is that the quote
> "Windows provides multiple ways to do it," he said. But DLL hijacking isn't limited to Windows, he said -- noting that it can apply to Macs and Linux, too.
is an artifact of the reporting, and not worth head scratching about.
The exploit would look completely different on Mac or Linux. As far as I know.
- joshumax 9y agoI was about to say this. My Debian machine updates software through apt + dpkg, and I installed Skype via the Skype repository. Why would Skype for Linux then choose to bundle its own updater, thereby breaking the integrity a package manager provides?
- rocqua 9y agoWould you really be certain a commercial company buisness is going to care about correctly packaging for a flavor of linux? Some companies wil do this, even more so if they work with FOSS and linux. But in general, especially for companies on the proprietary train, I wouldn't be so sure. If skype is in the base set of packages, I'd expect debian to require proper packaging. But if this is in some third party package, there are no such guarantees. That said, maybe some third party package that just installs the normal (auto-updating) version into /opt or /usr/local might be an option. It is better than having no installer, and shouldn't break too much of your package manager. Proper clean-up on uninstall is the only real issue I can think of.
- paulddraper 9y agoLots of programs I have try to update outside dpkg: Chrome, Intellij, VS Code.
- y0ghur7_xxx 9y ago> Lots of programs I have try to update outside dpkg: Chrome, Intellij, VS Code. Chrome and vscode have their own apt repositories. I don't know about intellij, but at least for the other two you just have to install them using their repos, and not using the dpkg package directly.