Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is exactly why I fight the windmills so hard when it comes automatic updates in Linux software.

So much damage is caused just by adding a single maintainer to a project - imagine how much power you would have to wield the remote execution systems put in place by naive developers for "automatic updates".

All it takes is a single malicious maintainer given access to the new version update of some popular user software, and they have a new botnet of thousands of devices at their disposal. Better yet, after the backdoor installation, they can just release the real update and cover their tracks forever.

Automatic updates are like running web applications, but without any sandboxing or protection usually implemented by the browser.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: