Served in the Krogan uprisings. Now I run a podcast

  • 2 Posts
Joined 1 year ago
Cake day: June 12th, 2023


  • Do you know if these folks actively develop it or do they just apply patches to the Firefox codebase ?

    Like do they just pre configure a bunch of about config settings and the pre installed search or do they harden the binaries at compile time ?

    I’ve not kept up with this but I’m curious if there is any real advantage of this over Firefox after it has been configured. If not I would stick with Firefox as it will get security updates quicker by people who know the source code intimately.

    Anyway not shitting on anyone’s choices here just curious.

  • Random hackers, companies, dragnet surveillance.

    The companies are probably the biggest exposure as we are forced to interact with them for utilities, flights etc . They get hacked all of the time and dont bother to secure their data.

    Also as a side note I hate how lots of places just assume you want to download their shitty spyware ridden apps or hand over your phone number or an email.

  • I’m curious to know about the distro maintainers that were running bleeding edge with this exploit present. How do we know the bad actors didn’t compromise their systems in the interim ?

    The potential of this would have been catastrophic had it made its way into the stable versions, they could have for example accessed the build server for tor or tails or signal and targeted the build processes . not to mention banks and governments and who knows what else… Scary.

    I’m hoping things change and we start looking at improving processes in the whole chain. I’d be interested to see discussions in this area.

    I think the fact they targeted this package means that other similar packages will be attacked. A good first step would be identifying those packages used by many projects and with one or very few devs even more so if it has root access. More Devs means chances of scrutiny so they would likely go for packages with one or few devs to improve the odds of success.

    I also think there needs to be an audit of every package shipped in the distros. A huge undertaking , perhaps it can be crowdsourced and the big companies FAAGMN etc should heavily step up here and set up a fund for audits .

    What do you think could be done to mitigate or prevent this in future ?