this post was submitted on 07 May 2025
199 points (98.5% liked)

Linux

54028 readers
1221 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 6 years ago
MODERATORS
 

The author addresses the issue.

you are viewing a single comment's thread
view the rest of the comments
[–] lorty@lemmy.ml 13 points 1 day ago (1 children)

Would anyone that installed their current system using ventoy be at risk? Should I reinstall?

[–] HayadSont@discuss.online 4 points 10 hours ago (1 children)

Would anyone that installed their current system using ventoy be at risk?

In absolute sense; we don't know for sure. It's possible to interpret this^[i.e. The lack of communication regarding this issue for more than a year, the recent finding in which fake root certificates are injected. And, of course, the maintainer finally addressing the issue.] in widely different ways:

  • Just the unfortunate occurrence of a set of uneventful events from an innocent party that tries to make up.
  • (OR) A facade (from a malignant/malicious party) in order to keep the communities' trust so that people continue to get caught in the web.
  • (AND) Anything in between*

Should I reinstall?

You should make up your own mind on that. The last time I installed an OS, I had become aware of this concern (i.e. the blobs). At that time, trusting it for what it was, would go against the threat model I've set for myself. And, consequently, if I had any (other) systems that were installed with it, then I would have proceeded to reinstall. But I'm not you, nor are you me... So, at the end of day, if you had something that resembled a threat model, then you would have used that to answer this question for yourself. As you don't seem to have one, making one just for this seems overkill. However, you could (re)assess how safe your system is in its current state and act accordingly. (Just to name a couple of examples:)

  • Do you just randomly run scripts that you've found on GitHub? Well, then this ventoy situation shouldn't be very concerning.
  • Do you deliberately refuse to install the unverified software on Flathub and only^[Within the context of Flathub. The packages found in the repo of your distro are trusted by default.] stick to its verified offering?* Then, you should seriously consider reinstalling.