I am tired of this sort of “concern trolling”. Why not talk about linux related problems in linux related forums and spare us of such discussions.
because I'm a FreeBSD user and am genuinely concerned. I don't run it in production I'm not that brave, but I still don't want malware to wreck my home lab. No trolling involved. Negative attitudes today seem to abound. I would ask for the post to be deleted because of the attitudes people are giving but I won't because I think the genuine answers given by some are important and are worth keeping for others.I am tired of this sort of “concern trolling”. Why not talk about linux related problems in linux related forums and spare us of such discussions.
Plus that *BSD usually don't draw that much attention...Bottom line, AUR allowed random Internet people to take ownership of unmaintained ports and change them.
As far as I understand, with FreeBSD-ports such option is not on the table.
Whether we have 250 or 25k out of 30k ports stale, is not a risk if we don't allow random people to touch them.
Plus that *BSD usually don't draw that much attention...
I think you got it a bit wrong.Bottom line, AUR allowed random Internet people to take ownership of unmaintained ports and change them.
As far as I understand, with FreeBSD-ports such option is not on the table.
Whether we have 250 or 25k out of 30k ports stale, is not a risk if we don't allow random people to touch them.
Edit. P.S. Arch User Repo is hosted by Arch Linux but managed by "the community".
Lately there has been a developer around promoting his ports/packages thing. When I commented that nobody sane should use a 3rd party ports/packages system of some guy, I got backlash on the level that FreeBSD should really allow this modus for the project, that people should be able to plug in their alternatives, that it is the spirit of BSD and the rest of the bullshit. Well, there is your answer.
I don't think there's anything that prevents something like FUR (FreeBSD User Repository) in addition to the existing portals, it's just a matter of having said repos and relevant signatures.Bottom line, AUR allowed random Internet people to take ownership of unmaintained ports and change them.
As far as I understand, with FreeBSD-ports such option is not on the table.
Whether we have 250 or 25k out of 30k ports stale, is not a risk if we don't allow random people to touch them.
Edit. P.S. Arch User Repo is hosted by Arch Linux but managed by "the community".
Lately there has been a developer around promoting his ports/packages thing. When I commented that nobody sane should use a 3rd party ports/packages system of some guy, I got backlash on the level that FreeBSD should really allow this modus for the project, that people should be able to plug in their alternatives, that it is the spirit of BSD and the rest of the bullshit. Well, there is your answer.
And, for the random internet person argument, aren't we all random people on the internet?
Is there any background check process to provide people with commiter access, and this by real legitimate entities?
How many times has "NPM" been attacked? Lots if I remember correctly. Different "repository" but similar output.Also, I don't think FreeBSD or any OS, closed or open source, is imune to these kinds of attacks.
That's trust-based and not really waterproof. A known committer with positive history can go there as well. While I only produce offline software, it would be interestinng to see an official checklist for administrators to avoid supply chain trouble.These are all completely different cases. The AUR problem is that it allows commits by non-committers, in effect. The XZ case was a carefully built up internet persona.
There is no formal background check.
That's trust-based and not really waterproof. A known committer with positive history can go there as well. While I only produce offline software, it would be interestinng to see an official checklist for administrators to avoid supply chain trouble.
The FreeBSD system is reliable thanks to a large amount of academic organisations that host the sources, so any fie difference will always be noticed soon. But how about the ports? What happens if a bad commiter plugs a rootkit in some obfuscated code that's auto-installed by make and makes it look like a nice visual update? Many users could build and install a malware as privileged user while unaware.
I am tired of this sort of “concern trolling”. Why not talk about linux related problems in linux related forums and spare us of such discussions.
It didn't have it and I've proposed changing to current form at Comment #13 here.This thread has "FreeBSD" right in the title.