this post was submitted on 07 May 2025
201 points (97.2% liked)

Linux

56278 readers
874 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 6 years ago
MODERATORS
 

The author addresses the issue.

you are viewing a single comment's thread
view the rest of the comments
[–] HayadSont@discuss.online 28 points 2 months ago (26 children)

Perhaps I'm too skeptical and/or have trust issues, but isn't this too little too late? This issue had been ignored for so long, but -suddenly- within 24 hours of this very peculiar find^[Spoiler alert: Ventoy's sister software -called iVentoy- employs a trick that has been utilized for installing compromised kernel drivers.], Ventoys maintainer goes into full damage-control mode. Should we just accept that?

Sorry, at least for now, I simply don't buy it.

[–] filister@lemmy.world 48 points 2 months ago (10 children)

The guy is trying to address the issue and he is building this in his free time. Give him some credit at least, I am sure this is consuming a lot of his free time.

I personally find this Ventoy an amazing piece of software and he also seems to be willing to address the issue and be more transparent in the future which is also commendable.

[–] HayadSont@discuss.online 18 points 2 months ago (9 children)

The guy is trying to address the issue and he is building this in his free time. Give him some credit at least, I am sure this is consuming a lot of his free time.

Fam, you've chosen to trust them for reasons that are unclear to me. Honestly, I don't see anything (yet) that would clear their name. For all we know, they could have ties to some intelligence agency; which the infamous Jia Tan has (retroactively) been accused of as well.

I personally find this Ventoy an amazing piece of software

That's not the issue. I've also made plenty use of it in the past. But at what point do you start to second guess the intent behind the maintainer?

he also seems to be willing to address the issue and be more transparent in the future which is also commendable.

Again, arguably too little too late. They literally ghosted the issue for over a year. Then, within 24 hours of possible proof of malicious code, they appear and (perhaps) "pose the image" of putting in a gargantuan effort to resolve the issue. But, like, where were they for a year? Furthermore, the hints of justifications for their actions are simply not up too par.

Don't get me wrong. As I clearly hinted at it in my previous comment, if they pull through and provide/produce (bit-by-bit) reproducible builds of Ventoy^[Another spoiler-alert: They admitted that it would be hard. Which is fine, but could be interpreted as the first action for an eventual cop out. Only time will tell...], then I obviously have no qualms against them or their software. Why would I? But until then, I will steer clear.

What should have happened for you to be more concerned?

[–] Vincent -4 points 2 months ago* (last edited 2 months ago)

There shouldn't be the need to clear a name, because you shouldn't be smearing someone's name who's giving away their work. It's fine to distrust it, but then just don't use the software.

load more comments (8 replies)
load more comments (8 replies)
load more comments (23 replies)