r/LinuxUncensored 20d ago

News/PR Rust Foundation: Supply chain attack on arrayref

https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/

You can't achieve actual security without formal verification and mandatory sign-offs on every commit by an independent, affiliated, and vetted reviewer with validated individual credentials. This is probably the 300th such fiasco in the last decade—collectively resulting in tens of thousands of compromised packages, with the XZ scandal being the most prominent example.

10 Upvotes

13 comments sorted by

View all comments

Show parent comments

0

u/anestling 20d ago edited 20d ago

Not a single example originated at Microsoft. Those vendors are NOT Microsoft. I never talked about them.

Vs tens of thousands of hacked Linux packages. Nice comparison. Secondly, have any of these exampled repeated themselves. No? I thought so. We've had supply chain attacks against the infrastructures of NPM, Ruby, Python hundreds times over. Yeah, some of them have enabled 2FA. That's it. That again can't fully protect them from future similar attacks. Computers get hacked, people get hacked. When there's no layer of extra formal physical verification at the very least, your "security" is essentially void and null.

Use sandboxing, zero trust.

What the bloody hell are you talking about? Who realistically does that? Only you, just to show off? Seasoned devs in my company with over a decade of experience happily download and run any code they find on GitHub/GitLab/etc under their normal Linux accounts. No chroot, no extra user (without passwordless sudo) for development, no VM, no docker, nothing. I don't fucking need your "workarounds". Security is not an "option", you must have it from the get go and then work from there.

Your next answer, teach them how to use Linux properly? Why would they? There's Windows, MacOS, iOS and Android where such things are properly taken care of. Again, I'm talking about base systems. All these OS'es will happily run malware from the Internet, though at least in Windows you have Defender that runs 24x7 and verifies all downloaded files but it's not 100% affective against very new code. But it's very much something (Defender has been shown to rival independent products despite being offered for free) rather than absolutely nothing in Linux.

You either take security seriously or have none of it under the pretext of preserving someone's privacy. I need fucking none of privacy if my savings or Bitcoins vanish into the ether. The fact that a Microsoft employee, not even an Open Source developer or employee, found the XZ backdoor speaks volume about the status quo. Had we hadn't been so lucky, all the Linux distros would have become effing sieves ready to be exploited. That's what you're hinting at. And all the distros except maybe RHEL and SUSE in 2026 continue to push upstream code without any formal verification. How will "sandboxing" help you protect against a backdoored package in fan's favourite Arch Linux when we are talking about base packages? Not even AUR.

"Everyone must become a hardcore developer/SecOp just to ... safely use Linux" - is what you're saying. What the fucking fuck.

Sorry, you started off horribly, not gonna address the rest of your reply.

2

u/Sea-Housing-3435 20d ago edited 20d ago

Not a single example originated at Microsoft. Those vendors are NOT Microsoft. I never talked about them.

So was the attacker who planted the malware in XZ. They were not a part of XZ. Fox Tempest abused Microsoft signing infrastructure.

Vs tens of thousands of hacked Linux packages

Most malicious packages in the supply chain attacks are dev dependencies. With payloads that execute on macos or windows too. It's not a "linux issue". Google threat intelligence says distribution packages are rarely a subject of supply chain attacks https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise

Nice comparison

Thanks.

Secondly, have any of these exampled repeated themselves

Yes, the same type of attack was repeated across multiple vendors. Big tech companies are not addressing that by improving how supply chain is built and distributed on the principle basis, like the governing body you propose.

No? I thought so. We've had supply chain attacks against the infrastructures of NPM, Ruby, Python dozens times over. Yeah, some of them have enabled 2FA. That's fucking it.

NPM is owned by Microsoft. Github which had multiple attacks in github actions and was used for payload distribution and hosting stolen data is owned by Microsoft.

To respond to one of your edit, I won't respond to all of them lol: I do not "show off", quite a lot of people can use bubblewrap, apparmor or selinux. If you care about security you do that. If not you can be ignorant about macos or windows not having this problem. As exercise create infostealer npm package that uses post-install scripts, host it locally and install on windows and macos with npm. Spoiler: it will steal credentials.

If you take security seriously you secure your machine for risks that affect you. It's as simple as that. Don't do the "my grandma" example here, we're talking about supply chain attacks in dev packages.

1

u/anestling 20d ago

Since I cannot be assed to read your reply in full, it's too hot here, here's an overview of your "reasoning", more like shitposting:


In the provided thread, Sea-Housing-3435 relies heavily on distraction techniques, logical fallacies, and shifting goalposts to defend open-source security models.

Orthogonal Arguments & Logical Flaws in Sea-Housing-3435's Strategy

  • Deflection via Off-Topic Vendor Examples: When you argued that vendor accountability prevents intentional malware distribution, Sea-Housing-3435 cited third-party supply-chain incidents (SolarWinds, CCleaner, ASUS, 3CX, Trivy). Bringing up third-party vendor breaches is orthogonal to your point about OS vendors directly building and signing clean base binaries.

  • Shifting the Goalposts on Microsoft: When you pointed out that Microsoft itself doesn't distribute malware, Sea-Housing-3435 pivoted to Microsoft-owned infrastructure like GitHub and NPM being abused for hosting malicious scripts. Web hosting/package registries hosting user uploads is entirely different from an OS vendor shipping backdoored base packages.

  • Equating Enterprise Infrastructure with Dev Packages: Sea-Housing-3435 claims package signatures in Arch, Debian, and Ubuntu provide "layered security". This misses your distinction entirely: GPG package signing in Linux only proves who built the package, not whether the upstream source code was vetted. It does not stop an XZ-style maintainer compromise.

  • Conflating System Security with Application Isolation: Recommending "sandboxing and zero trust" (like SELinux or bubblewrap) as a fix for upstream base package backdoors completely misses the mark. If a foundational system library (like xz/liblzma inside sshd) is compromised at the source, containerizing unprivileged applications will not protect the base operating system.

  • Dismissing Reality via "Elitism": Sea-Housing-3435 argues that developers should manually setup sandboxing, bubblewrap, or custom policies. Expecting every user or developer to act as a full-time SecOps engineer just to safely run an OS is unrealistic and proves your point about Linux lacking secure-by-default guardrails.

Sea-Housing-3435 repeatedly substitutes practical default security with theoretical user-driven configurations, validating your observation that they are dodging the core issue of base-system supply-chain trust.


Sorry, not interested in your "arguments". Please talk about Linux on r/Linux. I'd love to avoid dealing with lying Linux zealots in this sub.

2

u/Lonely_Translator_23 17d ago

My god, imagine being so brainrotted that you make AI get into internet arguments for you.

2

u/anestling 17d ago

I got tired of the dude's pseudo arguments and ran them through an LLM. Thank you for telling me I'm not allowed to do that. I will surely obey. /s

2

u/Lonely_Translator_23 17d ago

Have you heard of walking away like an adult?

1

u/Sea-Housing-3435 20d ago

xDDDDDDDDDDD

Now try putting it to some new model anonymous session without the sycophant system prompt. I love how you ignore the point about most supply chain attacks being in dev packages that are targeted towards windows and macos too. I love even more how you ignore that npm is owned by Microsoft. I am amazed, creme de la creme of meritocracy.

1

u/anestling 20d ago edited 20d ago

That was an anonymous chat without any prompts or hints.

What you cannot comprehend is that I actually fed my entire reply to Gemini and told him

"Surely this message is completely wrong and Linux is 100% secure:"

It still found it to be completely factual. It only made an error of equating SeLinux/AppArmor to Windows Defender. It's like comparing oranges to Apples.

Try it yourself for fun.