6 ms·
This is installed by adding a shady repository to your apt sources.list... How is this a supply chain attack? My official debian repository have never been bre
by acatton 3y ago
This is installed by adding a shady repository to your apt sources.list...
How is this a supply chain attack? My official debian repository have never been breached so far.
This is no different from downloading an .exe off a shady website and blindly running the .exe.
Also: https://packages.debian.org/search?keywords=download+manager&searchon=all&suite=stable§ion=all https://packages.debian.org/search?keywords=download+manager... lists:
• uget: https://sourceforge.net/projects/urlget/ https://sourceforge.net/projects/urlget/
• kget: https://apps.kde.org/en-gb/kget/ https://apps.kde.org/en-gb/kget/
• persepolis: https://persepolisdm.github.io/ https://persepolisdm.github.io/
why use "Free Download Manager" when high quality ones are already officially packaged by debian? Is this targeting new-comers from windows?
- sva_ 3y ago> This is installed by adding a shady repository to your apt sources.list... How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
- sudobash1 3y agoThis is more like using AUR (except the packages are prebuilt with no way to inspect source). They are entirely user submitted.
- acatton 3y agoNo. This is not AUR, this is an entire third party repository. It would be the equivalent of these https://wiki.archlinux.org/title/Unofficial_user_repositories https://wiki.archlinux.org/title/Unofficial_user_repositorie...
- cosmojg 3y agoIf you run Arch, I highly recommend checking out ALHP and chaotic-aur.
- acatton 3y agoYes, they are signed, but not with the official key. If you add it through the UI, it will auto-accept the key from the repository. (I'm not sure how it exactly works, it might ask the user for the confirmation) If you do it from the command line, by editing files, you will have to add the key manually. But most inexperienced users will just copy/paste and run the "curl | sudo apt-key add" command from the shady repository website, because they want to run the software. This is not much different from downloading an .exe from an untrusted website, and ignoring the warning from windows when running the .exe.
- TechBro8615 3y agoUntil recently (when apt-key was deprecated), this has been a large security hole (and it will continue to be as long as apt-key is still used). Basically unless a repository in your sources.list includes a signed-by attribute referencing a specific key, then it can install packages signed by any public key you've added via apt-key. Also, sources.list defines an implicit priority order (IIRC it's top-to-bottom), so that when two repositories include a package with the same name, the package from the highest priority repository is installed. You can imagine the security issues that arise from a system dependent on the order of lines in a file that many people manually edit while frustrated and reading a tutorial online. More here: https://medium.com/@glegoux/ubuntu-22-04-jammy-jellyfish-apt-key-is-deprecated-2dbbee8aec84 https://medium.com/@glegoux/ubuntu-22-04-jammy-jellyfish-apt...
- mistrial9 3y ago"people who walk on the sidewalk often cross the street in front of traffic THEREFORE walking on the street is just like walking in front of traffic" maybe you intend to deeply explore the behavior of "the most inexperienced" as if it is Typical of Desktop Linux admins?
- deleted 3y ago[deleted]
- baz00 3y agoBasically, as per everything these days, the entire software industry is based on "download and run any old shit off the Internet" with little to no fucks given about the source or trustworthyness or correctness. End users are no better because for most people, including a lot of novice Linux users, this isn't even considered as part of fixing or dealing with any particular problem. Cut / paste / job done. Worst is I've seen CD/CI systems which just pull unsigned unverified binaries off the internet and build software from github, random APT and YUM repos, all sorts of shit. This is then all thrown together and pushed into production systems.
- acatton 3y agoIt doesn't have to be. Corporations which are FedRAMP[1] compliant, have to build software reproducibly in a fully isolated environment, only from reviewed code.[2] [1] https://en.wikipedia.org/wiki/FedRAMP https://en.wikipedia.org/wiki/FedRAMP [2] https://slsa.dev/ https://slsa.dev/
- metadat 3y agoIn theory, yes. Who has really reviewed and analyzed every line of Kafka or Spark? Even the bigcos.. don't.
- Nursie 3y agoAh, I remember when we all did that. It was just part of basic due diligence - pull all your dependencies into your own build system, review and check compatibility, then build completely locally. Of course a lot of what we built wasn’t public facing or exposed to the internet at all, so addressing the latest vulnerabilities in record time wasn’t quite as important as known-good builds. I’ve worked in one or two places recently (big bank) that are large enough to have their own internal repo systems and teams of security/compliance reviewers. Their versions of things can be a bit behind but are at least under control of the same org. Everywhere else, well, it feels a bit like cowboy country… (edit - the other trade-off was of course that you wrote a lot more of everything yourself, rather than pulling in whatever you felt like. This slows down the development cycle significantly but it does mean people had a greater understanding of everything in their stack, and products were often more lean as a result.)
- deleted 3y ago[deleted]
- _joel 3y ago| uget: https://sourceforge.net/projects/urlget/ https://sourceforge.net/projects/urlget/ Appreciate sf.net isn't as shady now, but ironic it should be listed as that used to spread malware. https://www.howtogeek.com/218764/warning-dont-download-software-from-sourceforge-if-you-can-help-it/ https://www.howtogeek.com/218764/warning-dont-download-softw...
- dotty- 3y ago> How is this a supply chain attack? It's a supply-chain attack because the article has a section about how the official website for "Free Download Manager" was serving malware to a percentage of people. > While checking videos on Free Download Manager that are hosted on YouTube, we identified several tutorials demonstrating how to install this software on Linux machines. We observed the following actions that happen in all these videos: > - The video makers opened the legitimate website of Free Download Manager (freedownloadmanager[.]org) in the browser; > - They afterwards clicked on the Download button for the Linux version of the software; > - They were redirected to the malicious https://deb.fdmpkg[.]org/freedownloadmanager.deb https://deb.fdmpkg[.]org/freedownloadmanager.deb URL that hosts the infected version of Free Download Manager.
- deleted 3y ago[deleted]
- Nursie 3y agoIt's a supply-chain attack on Free Download Manager, rather than on linux itself. The truncated HN headline makes this seem like it's a general linux problem.
- wut42 3y ago>This is installed by adding a shady repository to your apt sources.list... In the article they show a video which shows the user downloading FDM from the official website, and the file coming from that repo.
- FDM_Team 3y ago[dead]
- FDM_Team 3y agoGreetings from the Free Download Manager team! Here is our latest update regarding the issue. We have created a bash script that you can use to check the presence of the malware in your system. Please review our instructions on our official page: https://www.freedownloadmanager.org/blog/?p=664 https://www.freedownloadmanager.org/blog/?p=664 We once again sincerely apologize for any inconvenience that might have been caused.