this post was submitted on 17 Sep 2024
431 points (99.1% liked)

Open Source

30379 readers
964 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
 

I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.

top 50 comments
sorted by: hot top controversial new old
[–] Antagnostic 199 points 3 days ago* (last edited 3 days ago) (4 children)

I was bored at work one day. I decided to put a nyan cat easter egg in my company's app. If at the loading progress bar screen you typed NYAN it would turn the progress bar into a rainbow being created by a little nyan cat while playing the nyan cat song. The mp3 (inconspicuously renamed without the extension) doubled our build size. No one batted an eye cause no one paid attention to the build size much.

Fast forward 5 years later, at a different job, I get a phone call from the old boss. Do you happen to know anything about this nyan cat file we found?

I had no idea what he was talking about.

[–] [email protected] 56 points 3 days ago (1 children)

Years and years ago I worked on a project where the logo was the outline of a head and an inward swirl for the brain.

For the website, if you held your mouse over it for 9 seconds, it would spin and flush. No one ever found that one that I know of.

load more comments (1 replies)
[–] [email protected] 22 points 3 days ago (7 children)

Aaaand thats why all commits should be signed with your pgp key

load more comments (7 replies)
[–] [email protected] 25 points 3 days ago
load more comments (1 replies)
[–] [email protected] 10 points 2 days ago (2 children)
[–] [email protected] 19 points 2 days ago (1 children)
[–] theherk 4 points 1 day ago
[–] AnUnusualRelic 1 points 1 day ago

They even made a movie about it!

[–] [email protected] 25 points 3 days ago (2 children)

Anyone who wants to fix this can help fix it, but people are just making demands of an unpaid maintainer. The devs can run this project the way they want to. If you don't like it, don't use Ventoy.

The people comparing this to the xz exploit are out of line. xz was a library that was deeply embedded in a lot of software. Ventoy is an IT tool used to boot live OSes. Not even remotely the same attack surface.

Blobs in the source tree are not ideal, but people need to pick their battles.

[–] [email protected] 4 points 1 day ago

If you don't like it, ~~don't use~~ fork Ventoy.

[–] [email protected] 47 points 2 days ago

From what others have said: The blobs violate GPL because they are taken from other FOSS project but the changes Ventoy makes are not viewable.

[–] [email protected] 29 points 3 days ago (1 children)

As a wise one once said: "Talk is cheap, send patches"

[–] [email protected] 7 points 2 days ago

Little did they know that Patches the Cat bit through their LAN lines and actually increased the cost of their communication.

[–] [email protected] 41 points 3 days ago

Glad it's getting a little more light. Been trying to tell people this for a few years now lol. It's the reason I've stayed away from it since first learning of the tool and looking at the "source code".

[–] mashbooq 78 points 3 days ago (2 children)

After I saw that issue, I attempted to build Ventoy from source. After making numerous modifications and getting only the first couple components built, I got tired of it and quit. I've made some modifications to glim and use that instead, although it's still not as easy as Ventoy. But I don't trust Ventoy if I can't build it myself.

Further, when @[email protected] made some criticisms of Ventoy in one of her YouTube videos, she was subjected to a harassment campaign, and others told her the same happened to them. That pushed me from not trusting Ventoy to actively distrusting it.

[–] [email protected] 42 points 3 days ago (2 children)

Further, when @[email protected] made some criticisms of Ventoy in one of her YouTube videos, she was subjected to a harassment campaign, and others told her the same happened to them.

What the fuck is happening to the world? Are we regressing or were we always this regressed and we've just given powerful tools to fucking chowderheads?

[–] [email protected] 30 points 3 days ago (1 children)

There's a subset of the Linux/FOSS/etc. community who are Conservative, misogynistic, racist, and/or otherwise general bigots. Compare the Ventoy-bros against the Elon-bros, and you'll see a similar pattern of behavior.

I don't personally understand it, since development is still sometimes seen as "work for weirdo nerds," so you'd think they would understand what it feels like to be rejected or bullied, but here we are. They manage to stay under the radar, because there's usually no reason to discuss politics or philosophy when you're debugging code.

[–] [email protected] 22 points 3 days ago* (last edited 3 days ago) (1 children)

There’s a subset of the Linux/FOSS/etc. community who are Conservative, misogynistic, racist, and/or otherwise general bigots.

right, the hackernews set...

[–] [email protected] 24 points 3 days ago

Don't know why you're being downvoted, hackernews is an awful site of smug, dumb software "engineer" tech bros with some of the worst takes on anything that isn't explicitly about how to code

load more comments (1 replies)
load more comments (1 replies)
[–] [email protected] 75 points 3 days ago (6 children)

I too wish the developer would respond, but I don't think this is the catastrophe people are making it out to be. One comment seems to explain why these binaries are included:

Because ventoy supports shim, and by extension secure boot, these files needs to come from a signed Linux distro. In this case they are taken from Fedora releases, and OpenSUSE apparently, as they publish shim binaries and grub binaries signed by their certificate.

[–] stickmanmeyhem 31 points 3 days ago (10 children)

If the hashes match the files from the Fedora or OpenSUSE releases, then does this really matter?

load more comments (10 replies)
load more comments (5 replies)
[–] [email protected] 55 points 3 days ago (3 children)

Hey guys open source is great you can look at all the code and therefore there are no security backdoors etc. Also here are a bunch of pre-compiled blobs in the repo, don't worry about those, but they are required to run the program.

[–] spankmonkey 88 points 3 days ago

The fact that people know there are pre-compiled blobs in open source means they have an informed reason to avoid the software!

[–] [email protected] 17 points 3 days ago

Right, the fact that it's open is the reason this came to light, and we're having this discussion

load more comments (1 replies)
[–] Feathercrown 50 points 3 days ago (4 children)

God I hate people who use github comments for their own benefit. "Just fork it bro" is never helpful.

[–] [email protected] 27 points 3 days ago (3 children)

For me the problem is more in GPL violation: they distribute blobs under GPL3, user made a request of the source code by creating an issue, but they ignored that request. It is not only about "you have to fix it" versus "just fork it" imo.

load more comments (3 replies)
load more comments (3 replies)
[–] [email protected] 26 points 3 days ago (4 children)

Wtf is ventoy and why is nobody explaining it

[–] Linkerbaan 31 points 3 days ago* (last edited 3 days ago) (3 children)

Basically an OS which let's you choose another OS to boot into. This way you can chose between multiple OS's on one USB drive. You drag your ISO files into a USB folder and choose between them on boot.

load more comments (3 replies)
[–] [email protected] 18 points 3 days ago (3 children)

Wtf is a BLOB and why is nobody explaining it

[–] [email protected] 24 points 3 days ago

Binary Large OBject

Basically any binary file, often objected to in open source repos because of the lack of source and 'openness'. See also the recent xz backdoor.

load more comments (2 replies)
[–] [email protected] 10 points 3 days ago (1 children)

because search engines exist

[–] [email protected] 30 points 3 days ago (2 children)

Wtf is search engines and why is no one explaining it

load more comments (2 replies)
load more comments (1 replies)
[–] [email protected] 30 points 3 days ago

Makes me wonder how far the closest alternative, glim, could be upgraded to match Ventoy given the confines of GRUB.

Someone had mentioned that Fedora fails to verify when booting from Ventoy. Now I'm thinking if I could dd the media loaded via Ventoy and compare with an original copy to see what changed.

load more comments
view more: next ›