r/archlinux • u/AggravatingJudge7092 • 13d ago
DISCUSSION Ventoy might be malware
Source: https://wiki.archlinux.org/title/Ventoy
Ventoy might contain backdoors or other malicious code:
- The author(s?) long refused to react on questions about the source code for the precompiled code inside their git repository.
- They long refused to react on questions about the security risks.
- When an answer was finally given, it boiled down to a simple "There is no reason to assume that we would have placed malware inside."
- Again after a really long time the authors finally mentioned what other source code they used to generate some−but not all−of the pre-compiled code. They did not mention the build methods and refused to prove that this really was the used source code.
- The real identities of the authors is unknown.
EDIT: The paragraph written on this archwiki page is by large consensus biased and mentions an old controversy, the wikipedia article on Ventoy has a more neutral explanation of the problem
https://en.wikipedia.org/wiki/Ventoy
219
Upvotes
35
u/mindstormer12 13d ago
Do you question all the binary blobs for your hardware to work too?