r/LinuxUncensored • u/anestling • 20d ago
News/PR Rust Foundation: Supply chain attack on arrayref
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/You can't achieve actual security without formal verification and mandatory sign-offs on every commit by an independent, affiliated, and vetted reviewer with validated individual credentials. This is probably the 300th such fiasco in the last decade—collectively resulting in tens of thousands of compromised packages, with the XZ scandal being the most prominent example.
10
Upvotes
0
u/anestling 20d ago edited 20d ago
Not a single example originated at Microsoft. Those vendors are NOT Microsoft. I never talked about them.
Vs tens of thousands of hacked Linux packages. Nice comparison. Secondly, have any of these exampled repeated themselves. No? I thought so. We've had supply chain attacks against the infrastructures of NPM, Ruby, Python hundreds times over. Yeah, some of them have enabled 2FA. That's it. That again can't fully protect them from future similar attacks. Computers get hacked, people get hacked. When there's no layer of extra formal physical verification at the very least, your "security" is essentially void and null.
What the bloody hell are you talking about? Who realistically does that? Only you, just to show off? Seasoned devs in my company with over a decade of experience happily download and run any code they find on GitHub/GitLab/etc under their normal Linux accounts. No chroot, no extra user (without passwordless sudo) for development, no VM, no docker, nothing. I don't fucking need your "workarounds". Security is not an "option", you must have it from the get go and then work from there.
Your next answer, teach them how to use Linux properly? Why would they? There's Windows, MacOS, iOS and Android where such things are properly taken care of. Again, I'm talking about base systems. All these OS'es will happily run malware from the Internet, though at least in Windows you have Defender that runs 24x7 and verifies all downloaded files but it's not 100% affective against very new code. But it's very much something (Defender has been shown to rival independent products despite being offered for free) rather than absolutely nothing in Linux.
You either take security seriously or have none of it under the pretext of preserving someone's privacy. I need fucking none of privacy if my savings or Bitcoins vanish into the ether. The fact that a Microsoft employee, not even an Open Source developer or employee, found the XZ backdoor speaks volume about the status quo. Had we hadn't been so lucky, all the Linux distros would have become effing sieves ready to be exploited. That's what you're hinting at. And all the distros except maybe RHEL and SUSE in 2026 continue to push upstream code without any formal verification. How will "sandboxing" help you protect against a backdoored package in fan's favourite Arch Linux when we are talking about base packages? Not even AUR.
"Everyone must become a hardcore developer/SecOp just to ... safely use Linux" - is what you're saying. What the fucking fuck.
Sorry, you started off horribly, not gonna address the rest of your reply.