How did the Ventoy blobs issue end?
from gomp@lemmy.ml to linux@lemmy.ml on 07 Dec 15:36
https://lemmy.ml/post/23321637

I remember a story where people asked about blobs included in Ventoy and there were no comments from the devs, leading to suspicion.

At the time it wasn’t clear to me if there was any substance to the story or if it was the usual Internet exaggeration, so I resolved to ignore it for the time being and saved a reminder to look into it after a while.

Now my reminder fired off and I looked around, but couldn’t find how the story ended… do you know?

#linux

threaded - newest

slazer2au@lemmy.world on 07 Dec 15:48 next collapse

I thought one of them did comment about it and it was something like the uefi drivers taken from Fedora or something.

bleistift2@sopuli.xyz on 07 Dec 16:06 next collapse

The issue is still open. github.com/ventoy/Ventoy/issues/2795

The last comment has this:

<img alt="" src="https://sopuli.xyz/pictrs/image/26cd818c-59ae-4e3f-8399-ba9676a1a61e.webp">

mumblerfish@lemmy.world on 07 Dec 21:08 collapse

That screenshot is from another site. An account named longpanda has also appeared on lemmy and had their post/replies removed because of impersonation suspicions.

I think it is wise to take extra care on this issue on what you read and trust.

exu@feditown.com on 07 Dec 21:52 next collapse

Afaik that particular post is on the official Ventoy forum. Probably legit

The Lemmy one was fake

priapus@sh.itjust.works on 08 Dec 15:22 collapse

That is the owners account from the official forum, which is known to be real. The Lemmy account was a fake that copied their name from that account.

rudyharrelson@lemmy.radio on 07 Dec 16:10 next collapse

I’m in a similar boat to you; whether the blobs constitute a security threat seems to still be up in the air. I read through the issue thread on github a few months back and it seemed the vast majority of the blobs were built by scripts contained in the repository, but some weren’t documented well, leading to uncertainty.

The comment by Long0x0 on Aug 05 lists a lot of the blob files.

Aatube@kbin.melroy.org on 07 Dec 16:26 next collapse

Blobs aren’t really a concern as they reference the sources which produce the same binaries, but there are suspicions of compromise due to the Lemmy comments mentioned in the thread. The official accounts’ comments alleviate some of that, though.

warmaster@lemmy.world on 07 Dec 18:06 next collapse

It didn’t end. Fuck Ventoy, I’ll use something else

neodc@sh.itjust.works on 07 Dec 18:21 collapse

What do you use in its place?

Telorand@reddthat.com on 07 Dec 20:28 collapse

GLIM is an option that is a little harder to use but has the ability to load up multiple ISO’s, and it is fully open source.

github.com/thias/glim

shekau@lemmy.today on 08 Dec 05:29 collapse

Last commit was over a year ago :|

FlappyBubble@lemmy.ml on 08 Dec 06:23 collapse

Presuming the software is working ans secure, is the time that passed since the last commit importang?

Telorand@reddthat.com on 08 Dec 14:12 collapse

I also check the open issues when I judge a repo, and there’s only 22, with nearly all of them being feature requests and not bug reports. Also, the majority were opened by the repo owner, and they’re checklist items for future functionality (like making less common ISO’s work).

It could be that it’s abandoned, or it could be that the maintainer just doesn’t have the time or drive to include edge cases like “NixOS” and “Fedora 37 clones” right now.

fool@programming.dev on 08 Dec 00:35 next collapse

Not fixed yet. People either quit, let their threat model allow Ventoy’s shellscripts to git-commit bins, or built it from source (i.e. PKGBUILD or ebuild).

IcyToes@sh.itjust.works on 08 Dec 12:49 collapse

Looks like contributor is busy with work. Always the risk with open source. If things aren’t raised in a reasonable manner, I can imagine the temptation is to follow it up with a middle finger.

Many seemed to care about it enough to bash it, but not enough to create and maintain a fork. They just want to boss it over the maintainer.

gomp@lemmy.ml on 08 Dec 13:42 collapse

Agreed: now that I’m looking at the whole thing, this looks like a story where the FOSS community left much to be desired.