I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.

201 points
*

I was bored at work one day. I decided to put a nyan cat easter egg in my company’s app. If at the loading progress bar screen you typed NYAN it would turn the progress bar into a rainbow being created by a little nyan cat while playing the nyan cat song. The mp3 (inconspicuously renamed without the extension) doubled our build size. No one batted an eye cause no one paid attention to the build size much.

Fast forward 5 years later, at a different job, I get a phone call from the old boss. Do you happen to know anything about this nyan cat file we found?

I had no idea what he was talking about.

permalink
report
reply
57 points

Years and years ago I worked on a project where the logo was the outline of a head and an inward swirl for the brain.

For the website, if you held your mouse over it for 9 seconds, it would spin and flush. No one ever found that one that I know of.

permalink
report
parent
reply
7 points

Should’ve included that in your FE analytics.

permalink
report
parent
reply
22 points

Aaaand thats why all commits should be signed with your pgp key

permalink
report
parent
reply
7 points

It sounds like they weren’t using any form of version control, so that’s definitely on them at this point

permalink
report
parent
reply
14 points

What makes you say that? To me, it sounds like that’s what they do have cause they tracked the change back to him. The commit message obviously said nothing about the file.

permalink
report
parent
reply
26 points

10/10

permalink
report
parent
reply
11 points

That story was a journey.

permalink
report
parent
reply
10 points

What does BLOB stand for?

permalink
report
reply
19 points

Binary Large OBject

permalink
report
parent
reply
4 points

Only kind of. That’s a backronym.

https://en.wikipedia.org/wiki/Object_storage#History

permalink
report
parent
reply
1 point

They even made a movie about it!

permalink
report
parent
reply
24 points

Anyone who wants to fix this can help fix it, but people are just making demands of an unpaid maintainer. The devs can run this project the way they want to. If you don’t like it, don’t use Ventoy.

The people comparing this to the xz exploit are out of line. xz was a library that was deeply embedded in a lot of software. Ventoy is an IT tool used to boot live OSes. Not even remotely the same attack surface.

Blobs in the source tree are not ideal, but people need to pick their battles.

permalink
report
reply
3 points

If you don’t like it, don’t use fork Ventoy.

permalink
report
parent
reply
49 points

From what others have said: The blobs violate GPL because they are taken from other FOSS project but the changes Ventoy makes are not viewable.

permalink
report
parent
reply
28 points

As a wise one once said: “Talk is cheap, send patches”

permalink
report
reply
7 points

Little did they know that Patches the Cat bit through their LAN lines and actually increased the cost of their communication.

permalink
report
parent
reply
42 points

Glad it’s getting a little more light. Been trying to tell people this for a few years now lol. It’s the reason I’ve stayed away from it since first learning of the tool and looking at the “source code”.

permalink
report
reply

Open Source

!opensource@lemmy.ml

Create post

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

Community stats

  • 5.5K

    Monthly active users

  • 892

    Posts

  • 6.6K

    Comments