I remember a story where people asked about blobs included in Ventoy and there were no comments from the devs, leading to suspicion.

At the time it wasn’t clear to me if there was any substance to the story or if it was the usual Internet exaggeration, so I resolved to ignore it for the time being and saved a reminder to look into it after a while.

Now my reminder fired off and I looked around, but couldn’t find how the story ended… do you know?

7 points

I thought one of them did comment about it and it was something like the uefi drivers taken from Fedora or something.

permalink
report
reply
52 points

The issue is still open. https://github.com/ventoy/Ventoy/issues/2795

The last comment has this:

permalink
report
reply
19 points

That screenshot is from another site. An account named longpanda has also appeared on lemmy and had their post/replies removed because of impersonation suspicions.

I think it is wise to take extra care on this issue on what you read and trust.

permalink
report
parent
reply
11 points

Afaik that particular post is on the official Ventoy forum. Probably legit

The Lemmy one was fake

permalink
report
parent
reply
5 points

That is the owners account from the official forum, which is known to be real. The Lemmy account was a fake that copied their name from that account.

permalink
report
parent
reply
32 points

I’m in a similar boat to you; whether the blobs constitute a security threat seems to still be up in the air. I read through the issue thread on github a few months back and it seemed the vast majority of the blobs were built by scripts contained in the repository, but some weren’t documented well, leading to uncertainty.

The comment by Long0x0 on Aug 05 lists a lot of the blob files.

permalink
report
reply
6 points

Blobs aren’t really a concern as they reference the sources which produce the same binaries, but there are suspicions of compromise due to the Lemmy comments mentioned in the thread. The official accounts’ comments alleviate some of that, though.

permalink
report
reply
-17 points
*

It didn’t end. Fuck Ventoy, I’ll use something else

permalink
report
reply
22 points

What do you use in its place?

permalink
report
parent
reply
13 points

GLIM is an option that is a little harder to use but has the ability to load up multiple ISO’s, and it is fully open source.

https://github.com/thias/glim

permalink
report
parent
reply
-1 points

Last commit was over a year ago :|

permalink
report
parent
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 6.4K

    Monthly active users

  • 4K

    Posts

  • 55K

    Comments