How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."?
I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonably well-known, but in the post it doesn't sound like he was a core maintainer, or even a very active community member. Do they just randomly hand out admin access to anyone?
For the record there are at least 2 distros that carry the Mandriva/Mandrake legacy. Besides OpenMandriva there is also Mageia which I believe is the more popular option.
Every time someone actively approaches you with an offer to spend their real energy and lifetime on your thing, It's almost always about leverage in some way.
At least if there is actual work attached to it.
Money alone might be paid by people that just have too much of it or want to feel better about something.
But if they actively involve themselves to a degree that goes way beyond scratching their own itch, something's up.
You might get lucky and find a just genuinely good person, but you might also not.
stop trying to make AUR sound like a place that can be compromised.
it's literary a tetanus ridden landfill, by design!
it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work)
the fact that idiots (in the original sense of the word in Greek) made automatic installers that fools novices to think those are vetted distro packages doesn't make it so.
AUR has always been a risk and that wasn't the first attack of that kind. And here... Well, if it was coordinated, they would've picked a distro that doesn't prompt responses like: "Oh, mandriva still exists?"
>feel like there's some organized attempt to paint Linux distros as dangerous.
imo the only ones doing that are the ones that try to portray the AUR as more than it actually is. A pastebin for package builds with "run at your own risk" all over it. It would be more concerning if there wasn't anything malicious found ever other day.
I had no idea mandriva/openmandriva still existed. I still have a mandrake cd somewhere, mostly because I cannot seem to be able to depart from physical media :)
I feel for the maintaners. There is a push and pull here on OSS.
However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam.
Because Im not dependent on PRs from randos this doesnt really matter to me.
I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host.
And go underground. Or decide whether the juice is any longer worth the squeeze. In my mind its not unless its off the internet. You may skate today, tomorrow you are completely screwed.
In the Stagex Linux distribution it is not possible for any single person to release anything. We require multiple independent review and reproduction signatures from the maintainer team.
We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.
I can not evaluate the claims made, but even if I am lenient and
assume it is all true, to me it is still strange how a distribution
becomes so dependent on a single person or provider. I can't help
but wonder how other distributions would have handled that; Gentoo
would probably not have ended in a similar situation, debian probably
neither.
And mind you - that's only if I evaluate the claims made at face value.
I also can't help but feel that there are some missing steps here. Sure,
IRC roid-raging happened in the past, see #freenode, and people are strange
in general, but even then it really reads oddly to me, almost as if "I trusted
that scammer from Nigeria with my money because the emails were so convincing".
Not deleting a comment like this says a lot about the project, none of which is good. The moderator replied, the commenter replied, yet the comment remains.
19 comments
[ 4.0 ms ] story [ 37.8 ms ] threadI feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonably well-known, but in the post it doesn't sound like he was a core maintainer, or even a very active community member. Do they just randomly hand out admin access to anyone?
Every time someone actively approaches you with an offer to spend their real energy and lifetime on your thing, It's almost always about leverage in some way.
At least if there is actual work attached to it.
Money alone might be paid by people that just have too much of it or want to feel better about something.
But if they actively involve themselves to a degree that goes way beyond scratching their own itch, something's up.
You might get lucky and find a just genuinely good person, but you might also not.
it's literary a tetanus ridden landfill, by design!
it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work)
the fact that idiots (in the original sense of the word in Greek) made automatic installers that fools novices to think those are vetted distro packages doesn't make it so.
Nah. Microsoft has better means to sell Windows.
imo the only ones doing that are the ones that try to portray the AUR as more than it actually is. A pastebin for package builds with "run at your own risk" all over it. It would be more concerning if there wasn't anything malicious found ever other day.
However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam.
Because Im not dependent on PRs from randos this doesnt really matter to me. I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host.
And go underground. Or decide whether the juice is any longer worth the squeeze. In my mind its not unless its off the internet. You may skate today, tomorrow you are completely screwed.
Fwiw, I don't think it's an "AI" problem, is a knowledge and respect problem from the people that have their agents dump code on FOSS projects.
unfortunately i did not add a note at the time
We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.
And mind you - that's only if I evaluate the claims made at face value. I also can't help but feel that there are some missing steps here. Sure, IRC roid-raging happened in the past, see #freenode, and people are strange in general, but even then it really reads oddly to me, almost as if "I trusted that scammer from Nigeria with my money because the emails were so convincing".
https://forum.openmandriva.org/t/statement-regarding-attempt...
Shameful.