Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Hacked – Installed a global KDE Plasma theme – it erased all my drives (reddit.com)
23 points by PKop on March 19, 2024 | hide | past | favorite | 13 comments


Global themes and widgets created by 3rd party developers for Plasma can and will run arbitrary code, That's how the do what they do. You are encouraged to exercise extreme caution when using these products.

Global themes do not only change the look of Plasma, but also the behavior. To do this they run code, and this code can be faulty, as in the case mentioned above. The code was not malicious, by the way, just wrong. The same goes for widgets and plasmoids.

We are already calling on the community to help us locate and quarantine defective software by using the "Report" buttons available on each item in the KDE Store.

Meanwhile, KDE is taking measures to properly warn users before each download and we are also putting in place ways of auditing and curating what is uploaded to the KDE store.

https://blog.davidedmundson.co.uk/blog/kde-store-content/

Nevertheless, this will take time and resources. We recommend all users to be careful when installing and running software not provided directly by KDE or your distros.

And remember to report any faulty products you find!


I think there are two problems with the message Plasma gives in that dialogue:

1. No warning about the arbitrary code - a "theme" intuitively looks like something that should contain art, not code.

2. Users develop banner blindness and ignore that message.

Well-tested themes need a lot of work many theme creators aren't ready for. They're rare. Maybe rename/redesign that dialogue to give an impression of a collaborative workshop where users are expected to be participants (developers and testers), rather than an application store with finished products in which they are consumers?


Themes. Open source. Running executable code without review.

This isn’t only a KDE problem but I think it very much is a KDE trap.

I think it’s a little like flying an aircraft. If you’re not doing the maintenance and safety checks then you’d better pray there is a trust worthy actor doing it.


> Themes. Open source. Running executable code without review.

Call me naive, but I was surprised to discover a theme pack could contain arbitrary executable code. Apparently they can contain/install custom "plasmoid" widgets, which I guess makes sense, but it's apparently obvious.

The user seemed to install the theme through something suggested by the desktop environment without seemingly making it clear that it was unverified, unsourced user submitted code. This doesn't seem obvious or like a calculated risk.

Linux users by definition trust their distribution. The distribution recommends and installs the desktop environment - the user should also be able to trust the DE. The DE recommends to install something sounding benign - I can see exactly why the user wouldn't treat that with due suspicion.


KDE explicitly warns you that the content installed through the "Get New..." dialogue (like that person did) is from the untrusted third parties, although it doesn't warn that it can contain executable code. This is the message it gives:

>The content available here has been uploaded by users like you, and has not been reviewed by your distributor for functionality or stability.


> The user seemed to install the theme through something suggested by the desktop environment without seemingly making it clear that it was unverified, unsourced user submitted code.

Any source of that statement? I'm pretty sure it made it clear the last time I saw the KHotNewStuff dialog, which was about a week ago.


Like..Tom Cruise?


TL;DR

https://old.reddit.com/r/openSUSE/comments/1biunsl/hacked_in... has the smoking gun

> That all said, this is a plasmoid that was written for KDE 5. Maybe some interaction with KDE6 lead to the issue? One issue that could have happened is that property string configPath <SNIP> now uses another StandardPaths.standardLocations due to KDE6. This could lead to configPath looking like somepath / (note the space), which expands to sh save.sh somepath / ..., which will happily remove everything. The whole situation reminds me of the Steam uninstaller, where a single space had some remarkable results.


>This could lead to configPath looking like somepath / (note the space), which expands to sh save.sh somepath, which will happily remove everything.

Obligatory classic:

https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/commi...


> The whole situation reminds me of the Steam uninstaller, where a single space had some remarkable results.

https://github.com/valvesoftware/steam-for-linux/issues/3671



*drivers


Drives. OP explains the typo




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: