10 ms·
Using browsers to download software should never have become the standard practice... Linux got it right with the built-in package repositories. Unfortunately
by jamieweb 8y ago
Using browsers to download software should never have become the standard practice...
Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.
- redial 8y agoHow would you know what "this" should be without using a browser?
- s3m4j 8y ago1. You search info about "this" in your browser 2. You install "this" with your package manager 3. Even if the "this" installed wasn't the "this" you read about in your browser, it still came from your package manager repos, which you could consider safe, and you'll be able to uninstall it cleanly. Then I look at the Windows Store and weep.
- orev 8y ago“apt search this”
- Xylakant 8y agoapt search chrome. Good luck with that on a default Debian install.
- jamieweb 8y agochromium-browser is the one. Although on Ubuntu it's in the Universe repository, so you have to add the chromium-team ppa in order to get on-time updates. I will admit that Chrome/Chromium is one of the few things you can't easily get from the repos, on Ubuntu at least.
- Xylakant 8y agoSo how does that prevent a malicious PPA or repo that the attacker could push up in the search rankings? Just like the attacker here pushed up a malicious download page in the search rankings?
- jamieweb 8y agoIt doesn't in this case, however you can determine that the chromium-team ppa is the official one in Ubuntu by following links from the Chromium website. The security of the package repository system falls down when people add apt signing keys that are untrusted/unverified, which is what happens when you add a ppa in Ubuntu.
- stordoff 8y ago> you can determine that the chromium-team ppa is the official one in Ubuntu by following links from the Chromium website. We're sort of in a loop here -- how can I know what is the official Chromium website?
- jamieweb 8y ago> We're sort of in a loop here Yeah, unfortunately that's what verifying the legitimacy of the chromium-team Ubuntu ppa requires... Anyway, there are two quick ways I found: * Go to chrome://settings/help and see the link to Chromium.org (but obviously this doesn't work if you don't have Chrome already) * At the bottom of google.com/chrome there is a link to Chromium.org
- michaelmrose 8y agoDebian prioritizes being open source over being user friendly. Googling debian google chrome results in instructions for getting chrome on debian. I have 3 different distros installed on 3 different computers. Chrome is listed on all app searches.
- Xylakant 8y ago> Googling debian google chrome results in instructions for getting chrome on debian. Yes. I know. I'm not picking on debian specifically here, fedora's dnf doesn't help you install chrome either. My point is rather the following: The GP asserts that the way to find (and subsequently install) software is "apt search `software`" and that way breaks down on exactly the piece of software that the article is about. You have to google instructions and then install either the .deb or add googles repo. And that's where the attacker could just as well insert an ad pointing you to a malicious repo. Just as the attacker currently points people to a malicious download. So the GPs solution isn't a solution at all. Not to this problem.
- jamieweb 8y agoGP's solution is valid for the majority of software - at least the sort of software that us HN folk probably use. Unfortunately Google Chrome is a bad example here as it's not available in most repos (since it's closed source).
- Xylakant 8y ago> GP's solution is valid for the majority of software - at least the sort of software that us HN folk probably use. That’s a bold statement to make, especially since a single piece of malicious software is sufficient. And yes, I want chrome. I need chrome. I need to test stuff on chrome.
- michaelmrose 8y agoGoing to googles official webpage will tell you how to get chrome for Debian/Ubuntu/Opensuse/Fedora. This is about as good as it can be because chrome is closed source. Chromium is available in the repos.
- beager 8y ago`apt install this` would be problematic at App Store/Play Store scale, though. I agree that search engines as an intermediary don't do enough to curb confusion, but exploitation of `apt` and other "more stable" distribution channels is prevented not as much by their design superiority than by the risk/reward dynamics of their incentive structures.
- pjc50 8y agoTrue, this was one of the things that originally appealed to me about Linux. But on a for-profit operating system this turns into an "app store" which gets to pick which software is and isn't allowed, while taking a 30% cut of the profits.
- sandov 8y agoAs if distro mantainers didn't get to pick which software is and isn't allowed.
- Kliment 8y agoSure they do, and there's usually an official first-party process to add repositories not approved by the distro maintainer. As far as I am aware neither the microsoft nor the apple app stores allow this.
- matt4077 8y agoThe Mac experience is almost identical, except that the App Store has a GUI (although Linux distributions also have those these days, I hear). Apple regularly gets lots of grief here because people have been suspicious they want to shut down distribution outside of the store. I have my doubts that any Linux distribution is capable of auditing every line of every package they distribute, so I think the relative lack of malware on Linux (and possibly MacOS as well) may not actually be caused the specific method of distribution.
- jamieweb 8y ago> The Mac experience is almost identical I don't agree. If you search for "chrome" or "firefox", you will get a page full of spammy apps that are anything but what you searched for. Linux distributions probably don't audit every single line of code in the packages, however this is code written by trusted developers that is mandated to be open source and distributed through official channels. Getting malware into the package repositories would be very difficult, but it seems that getting a fake Google ad on Bing is very easy, so in my opinion the distribution method makes a big difference.
- partiallypro 8y agoYeah, I mean obviously what the average users wants it to have to type in apt get commands and finding the slug to get the right package instead of clicking a link. Very intuitive. You know how Google & Firefox could easily help fix this? List their browsers in the Mac and Windows Store.
- gpm 8y agoPackage managers have had nice gui front ends for a long long time. The first earliest I'm aware of (which is to say it came with the first linux distro I ever used) is synaptic [0]. Looks like it was first released in 2001... The interface for this is "start nice gui front end, type firefox into search bar, select firefox package, click install" [0] https://en.wikipedia.org/wiki/Synaptic_%28software%29 https://en.wikipedia.org/wiki/Synaptic_%28software%29
- rhizome 8y agoThere are GUIs for most if not all Linux package managers.
- Dylan16807 8y agoBrowsers are banned from the Windows Store. For 'security' reasons. It's tricky to get win32 apps in general into it, too.
- jamieweb 8y agoIs that the same for the Mac App Store? Looks like browsers aren't in there either.
- partiallypro 8y agoNo they aren't, the UC Browser is listed in the Windows store (third most popular mobile browser in the world,) along with some others. Microsoft has been very willing to help companies list Win32 apps in the Windows store, especially large ones.
- Dylan16807 8y ago
- sandov 8y agoPackage managers are a fundamentally flawed concept: You depend on your distro mantainers to package what you need to install. If it isn't packaged, best case scenario is you get a tarball, which is already too hard for 99% of computer users. Snaps and Flatpaks are still too unpolished. Getting all your user applications (DAW, IDE, etc) from your OS developer (instead of getting it from the application developer) is also against the sentiment of freedom that so many Linux users preach.
- beagle3 8y agoNo. Ubuntu makes private package archives (PPAs) very simple to use; many packages are available from the maintainer’s PPA. There are many alternative repositories for essentially all distorts today; snaps and flatpaks are indeed not yet polished enough, but they are much better and easier for 99% of users than tarballs, so calling tarballs a “best case scenario” is, in my opinion, wrong.
- tsimionescu 8y agoAnd how are PPAs fundamentally different from downloading a Windows installer from the Internet? If I download the installer from the maintainer's site, there's 0 risk (assuming HTTPS). And the site giving the PPA link is just as likely to be a phishing site as the the one serving some exe. Except browsers will sometimes warn on strange executables, whereas none do on misleading PPA links.
- beagle3 8y agoMoving the goal posts much? You were complaining tarballs are the “best case” and are not good enough because they’re too hard for regular users. PPA is as easy as windows downloads; it updates the same way as the main system unlike windows; and it always go through ununtu’s Servers which makes it somewhat more monitorable. But that’s a new discussion.
- Too 8y agoBoth windows and mac have built in app stores which are the equivalent of package managers. But package managers can also have lookalike names. Npm and pip has had a few famous misspelled common packages that contained malware instead. Those are more open than apt or the big app stores but even on Google play you will find tons of lookalikes. This whole incident just shows you should never just search for anything by name and pick the first good looking result. You really have to verify the source regardless of which search engine you are using. What I very much dislike is companies who refer to their own app in the app store only by name and then you when you search you get 10 results which all look equally shady. And because they outsourced the app development the publisher doesn't even match. Place a god damn link or show the unique package name on your websitr instead.
- kayone 8y agoI've been trying to solve this for windows, take a look at https://appget.net https://appget.net if you use windows.