6 ms·
You are aware that VLC, LibreOffice and many other FOSS apps have an update checker?
by LeoWattenberg 11mo ago
You are aware that VLC, LibreOffice and many other FOSS apps have an update checker?
- cookiengineer 11mo agoThe problem is not the update check itself, but what the server in Moscow returns. That's the whole point and the reason of me mentioning it.
- CamperBob2 11mo agoNot good to hear they're based in Moscow, but that ship has presumably already sailed and sunk if you're running the auto-update code in an existing Audacity installation. What other concerns besides national origin exist with this code? Nothing seems to qualify as a "back door," certainly.
- cookiengineer 11mo agoSet the system language and timezone, the IP and originating ASN, to areas where APT28/APT29 is having active malware campaigns and see whether you'll receive a sample. Pretty simple. The real question is whether they have changed their C2 behaviors since Valentine's day in 2023, and whether or not the AstraL1nvx botnet operator images are still available publicly.
- LeoWattenberg 11mo agoplease provide any sort of source that Audacity is, or ever has been, distributing malware.
- deleted 11mo ago[deleted]
- Orygin 11mo agoHe has none and has been trying to depict Audacity as a Russian malware vector for over a year now, but without providing any source.
- cookiengineer 11mo agoTechnically it's been over 4 years
- h4ck_th3_pl4n3t 11mo agoSneed
- LeoWattenberg 11mo agoThere is no server in Moscow, and I don't think there ever was. Muse Group left their original office in Kaliningrad for Cyprus pretty much the second the war started, and at this point has no offices or employees left in Russia. The servers always have been bog-standard cloud things, so Cloudflare, DigitalOcean, aws via Netlify and such.