7 ms·
This is really scary for those who manage multiple things. I'm considering running a factory reset on everything from my router to my Steam Deck and remote serv
by Shellban 1y ago
This is really scary for those who manage multiple things. I'm considering running a factory reset on everything from my router to my Steam Deck and remote server.
- gpm 1y agoUh... did you install these AUR packages? It seems quite unlikely you installed these on either a router or a steam deck... That said, if you did, yeah being hacked is scary and I feel for you.
- johnisgood 1y agoI wonder if he even has any unofficial packages installed.
- Shellban 1y agoI had the regular librewolf-bin package installed on a couple of my machines. It took me a bit of time to note that librewolf-fix-bin is something separate.
- johnisgood 1y agoYeah do not worry, you are fine. https://aur.archlinux.org/packages/librewolf-bin#comment-1032783 https://aur.archlinux.org/packages/librewolf-bin#comment-103...
- Shellban 1y agoAs @lillylizard pointed out, it turns out that these are new packages, not comprised existing packages like I first thought. Still, the nature of the hack is a Remote Execution, as you pointed out elsewhere, meaning the hacker could pull my router password from the password manager, or grab my SSH keys and log into whatever machine is listed in the known_hosts, or just mess with my Ebay account and the credit card saved on there. The hacker could in theory do literally anything I could do.
- akerl_ 1y agoSure, but only if you’d installed the affected AUR packages. Even if they were old packages, probably your SteamOS didn’t install them from the AUR.
- Shellban 1y agoWhether or not SteamOS installed them is irrelevant. All the hacker would need is to compromise a machine that had some sort of remote access to other devices (ssh in this case, with some sort of keylogger to decrypt the private key).
- nulld3v 1y agoYou are not compromised unless you specifically installed one of these 3 packages on one of your machines: - librewolf-fix-bin - firefox-patch-bin - zen-browser-patched-bin The packages were only available for download for 3 days, and the only way you could have installed them is if you explicitly typed one of the package names into your terminal within those 3 days. Did you do that? If no, then you are not compromised.
- pndy 1y agoI wonder if this is really about compromised packages or rather in wider view trying to paint Arch, AUR as insecure.