3 ms·
> Themes. Open source. Running executable code without review. Call me naive, but I was surprised to discover a theme pack could contain arbitrary executable
by BuildTheRobots 3y ago
> Themes. Open source. Running executable code without review.
Call me naive, but I was surprised to discover a theme pack could contain arbitrary executable code. Apparently they can contain/install custom "plasmoid" widgets, which I guess makes sense, but it's apparently obvious.
The user seemed to install the theme through something suggested by the desktop environment without seemingly making it clear that it was unverified, unsourced user submitted code. This doesn't seem obvious or like a calculated risk.
Linux users by definition trust their distribution. The distribution recommends and installs the desktop environment - the user should also be able to trust the DE. The DE recommends to install something sounding benign - I can see exactly why the user wouldn't treat that with due suspicion.
- seba_dos1 3y ago> The user seemed to install the theme through something suggested by the desktop environment without seemingly making it clear that it was unverified, unsourced user submitted code. Any source of that statement? I'm pretty sure it made it clear the last time I saw the KHotNewStuff dialog, which was about a week ago.
- orbital-decay 3y agoKDE explicitly warns you that the content installed through the "Get New..." dialogue (like that person did) is from the untrusted third parties, although it doesn't warn that it can contain executable code. This is the message it gives: >The content available here has been uploaded by users like you, and has not been reviewed by your distributor for functionality or stability.