Ventoy is a tool to make a USB with multiple ISOs bootable, letting you select which ISO to use on boot. Another newly-created account claims to be the dev’s friend and translator and has received no contact from the maintainer.

  • @[email protected]
    link
    fedilink
    English
    12
    edit-2
    10 hours ago

    so ive deep dived into as much information as i can find. the TLDR is the main dev LongPanda supposedly went on a vacation to china (most likely his home country?) to which there is conflicting information on his return. one path is he make a lemmy account 9hours ago and made a message that doesn’t describe the blob and sound like a gpt response. to which his "irl friend made an account 3 hours ago to comment that he hasnt heard from LongPanda in months. both were removed from lemmy.ml because of suspected impersonation. the other side of the coin is the LongPanda is still gone and hasn’t addressed the blobs. after looking thought the documentation, you can build from source. in the instructions it says "5. Binaries

    There some binaries in Ventoy install package. These files are downloaded from other open source project’s website, such as busybox."

    i am not a programer but in the source build it lists the blobs and were there from supposedly from other FOSS projects with sha256’s. so theoretically you should be able to verify the blobs, with the sha256.

    https://github.com/ventoy/Ventoy/blob/master/DOC/BuildVentoyFromSource.txt

  • @callcc
    link
    3814 hours ago

    Nobody knows who responded here. Don’t spread rumors.

    • AatubeOP
      link
      fedilink
      414 hours ago

      I thought it was clear from the details that it was suspicious. Edited.

      • @callcc
        link
        56 hours ago

        Things are suspicious but you still spread gossip and maybe lies.

  • Quack Doc
    link
    2614 hours ago

    My name is Linus torvalds and this is why I TempleOS…

    • @db2
      link
      312 hours ago

      My name is TempleOS and this is why I Linus Torvalds

  • @just_another_person
    link
    1012 hours ago

    I understand the concern raised, but unless I’m reading this wrong there is an assumption that Ventoy may be doing something untoward, but I’m not sure how at this level. It can’t inject anything into the ISO files at rest without bricking then, and I don’t know if an OS that doesn’t verify it’s own image before booting.

    Just sounds like super lazy project administration. Maybe I’m missing something?

    • AatubeOP
      link
      fedilink
      1312 hours ago
      1. Around April, there was this big thing where a maintainer for XZ Compression included an SSH backdoor in binaries that were only built on release. If a freaking piece of compression software can backdoor SSH, who knows what else is possible.
      2. The response to the blob concern is nonsensical, made without their previously-known accounts, and coincides with someone’s claim that they are a close friend and was on vacation to China, the country where the XZ maintainer was from.
      • @just_another_person
        link
        1012 hours ago

        The xz issue is something totally different though. That was a software library running and executing against flat files. I’m just not sure there’s a way to alter an ISO image before boot, undetected in the case of Ventoy.

        If the goal is to alter files to provide access to something, this must be some sort of ingenious way that bypasses checksums, and targets something universal, which doesn’t seem quite possible in the case of a substitute bootloader.

        • AatubeOP
          link
          fedilink
          212 hours ago

          Yeah, it would be really big. I wouldn’t have posted about this if it weren’t for the radio silence and blabbering statement.

  • @[email protected]
    link
    fedilink
    4
    edit-2
    14 hours ago

    Interesting context to bring up Lemmy

    Edit: from the thread, it’s pretty clear those people were not the creator?

  • @[email protected]
    link
    fedilink
    -710 hours ago

    I heard people raving about ventoy, i checked it out online, but blobs and chinese maintainer made it seem fishy. Even if a maintainer was legit it only takes CCP thteatening their family to get a backdoor inserted

    • @[email protected]
      link
      fedilink
      139 hours ago

      This is ridiculous. You don’t trust “Chinese maintainers” (“even if legit” lol), because the “CCP” might threaten “their family to get a backdoor inserted”.

      Absolutely unhinged level of fantasy in the context of this project. A nation of 1.4 billion people and you don’t trust anyone there to write software? You know they made your phone and pretty much everything else right? Also, the idea that “the CCP” is somehow uniquely (among governments) willing and able to coerce or commission backdoors in software is a feverishly deluded attitude.

      Propaganda has put a backdoor in your brain.