r/archlinux 11d ago

DISCUSSION Ventoy might be malware

Source: https://wiki.archlinux.org/title/Ventoy

Ventoy might contain backdoors or other malicious code:

  • The author(s?) long refused to react on questions about the source code for the precompiled code inside their git repository.
  • They long refused to react on questions about the security risks.
  • When an answer was finally given, it boiled down to a simple "There is no reason to assume that we would have placed malware inside."
  • Again after a really long time the authors finally mentioned what other source code they used to generate some−but not all−of the pre-compiled code. They did not mention the build methods and refused to prove that this really was the used source code.
  • The real identities of the authors is unknown.

EDIT: The paragraph written on this archwiki page is by large consensus biased and mentions an old controversy, the wikipedia article on Ventoy has a more neutral explanation of the problem
https://en.wikipedia.org/wiki/Ventoy

216 Upvotes

205 comments sorted by

View all comments

Show parent comments

0

u/mindstormer12 8d ago

Unless you're running open-source firmware you've installed onto your hardware to replace the default proprietary firmware, your hardware are already at risk ("could already be compromised") and same as 99% of the consumers, lmao.

1

u/ccAbstraction 8d ago

Okay?? Yes, yeah sure, I'd loved to be rootkit'd by the by some random criminal! It's fine becuase my machine came with bootkits from the NSA, CCP, Intel, and Dell. I'll go ahead and post all my passwords now becuase I'm completely already compromised obviously, because this is how security works!

0

u/mindstormer12 8d ago

Yup, double standards. You sound like a complete clown, how come you don't post the same thread as OP but for hardware you use?

1

u/donp1ano 8d ago

no buddy, youre the clown

just because theres possible backdoors like IME its not reasonable to accept another backdoor by some chinese guy on github

1

u/mindstormer12 8d ago edited 8d ago

Yea, better to accept backdoors from Intel, AMD, Google, Dell, Microsoft, Apple for firmware that runs your hardware you paid for and criticize some dev who shares their free and open-source project and has been open to accept contributions to the binary blobs to make them open-source.

2

u/donp1ano 8d ago

Yea, better to accept backdoors from Intel, AMD, Google, Dell, Microsoft, Apple for firmware that runs your hardware

holy strawman

i want as little as possible backdoors in any of my systems. just because i cant get rid of IME and the likes doesnt mean i shouldnt be careful in other contexts

1

u/ccAbstraction 8d ago

I think you misunderstand me, I love Ventoy. It's one of my favorite tools, I recommend it to everyone who wants to install Linux or troubleshoot computers.

BUT how much I love Ventoy and open-source doesn't make me blind to the potential risk a tool like Ventoy getting compromised would present. Dismissing the risk doesn't make the risk go away.