7 ms·
OpenMandriva: Statement regarding attempted distribution sabotage
- crote 2mo agoHow did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."? I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonably well-known, but in the post it doesn't sound like he was a core maintainer, or even a very active community member. Do they just randomly hand out admin access to anyone?
- throw1234567891 2mo agoThere aren’t, they just don’t write it because it’s shameful for them. They trusted a man who brought two more people in, and they thought they were sheriffs.
- OhSoHumble 2mo agoIt's hard to maintain open source software that needs infrastructure. Everyone is a volunteer and it's not like the Mandriva project has the resources to fully vet people as well as have a high quality RBAC and access control system. This guy sounds like maintained a large project, offered to help, and Mandriva saw the Trojan horse as a way to alleviate a lot of their problems. And it didn't sound like he was able to "nuke everything" - it sounds like he had access to their repository infrastructure (which is reasonable given he was volunteering to host it) and then lashed out. If anything, I think it's a bigger organizational red flag that they agreed to privately host their source code on some random git forge and not a larger, more communal one. I mean, even if they didn't want to use GitHub (did this even cost money for them) then there are other providers to choose from. It just sounds like the Mandriva maintainers are trusting and good folk who may be overworked running an open source project and that led to a bad apple entering the bunch. It's hard for me to be mad in that kind of situation.
- lenerdenator 2mo ago> It just sounds like the Mandriva maintainers are trusting and good folk who may be overworked running an open source project and that led to a bad apple entering the bunch. It's hard for me to be mad in that kind of situation. It's hard to be mad, but people in FLOSS need to start taking this sort of cautionary tale to heart, particularly when it comes to Linux distros. If you don't have a good way to sustain maintenance and development of a software project in the current era - one with LLM spam, social engineering, and apparently, jackass contributors - you need to start looking into ways to wrap the project up and focus your energies on more established projects that might need help. I know that sounds mean, but this isn't just a hobby project anymore. This is an operating system. People put their entire lives on their computers. It's not a failure, you can do everything right and end up in a situation like we see here.
- account42 2mo agoPeople don't need to do anything when they are volunteering their free time - they can run a distro that is not up to your standards if they want to.
- lenerdenator 2mo agoThen I don't want to hear sob stories about how someone nuked half of the public repo, or how someone managed to put a backdoor in some low-level dependency that half of the world's servers rely on. I also don't want them to expect to be taken seriously, either. It's not the 00s anymore. You are not special if you can post code that compiles to a central repository where people can duplicate and modify it. There are entire colleges in most developed nations that have 18-year-olds who can do the same thing now. The key to being taken seriously is figuring out how to do that sustainably and responsibly.
- phantompeace 2mo agoWhy did you consciously click into this article and comments section if you don't want to hear about it? You're free to scroll on at any time.
- ShinyLeftPad 2mo ago> How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub What's unclear? This guy was part of the project for some time and got maintainer trust. Then he brings in his mate. His mate is a crap person and gets kicked out of the project. The original guy then goes bananas and nukes stuff.
- crote 2mo agoI have been part of the HN community for a while as well. I don't have admin access to its servers. That's the unclear part. How does it go from "offering to host it, which is refused" and "read-only mirror" to... this?
- account42 2mo agoBeing a commenter on a forum is different from being a contributor to an open source project.
- ShinyLeftPad 2mo agoI understood that he was part of the team not just community. Think dang, not a random commenter. I'm pretty sure mods here have priveleges we don't.
- whalesalad 2mo agoTIL Mandriva/Mandrake Linux is still around.
- jitix 2mo agoMe too. It was my first Linux back in 2003 and I was immediately hooked. Back then codecs weren't as much of an issue as they were in the late 2000s to early 2010s so everything worked out of the box and the performance on Pentium 4 with 128 MB RAM was phenomenal compared to Windows XP. I'm so glad the project is still around.
- prmoustache 2mo agoFor the record there are at least 2 distros that carry the Mandriva/Mandrake legacy. Besides OpenMandriva there is also Mageia which I believe is the more popular option.
- moondowner 2mo agoRelated, Mageia 10 was recently released (June 30, 2026). https://9to5linux.com/mageia-10-officially-released-with-linux-kernel-6-18-lts-kde-plasma-6-5-and-more https://9to5linux.com/mageia-10-officially-released-with-lin...
- hypfer 2mo agoI feel like this is kinda sorta to be expected. Every time someone actively approaches you with an offer to spend their real energy and lifetime on your thing, It's almost always about leverage in some way. At least if there is actual work attached to it. Money alone might be paid by people that just have too much of it or want to feel better about something. But if they actively involve themselves to a degree that goes way beyond scratching their own itch, something's up. You might get lucky and find a just genuinely good person, but you might also not.
- pndy 2mo agoNearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.
- notatoad 2mo agoi mean, they're succeeding. whether it's coordinated or not the conclusion is the same. but i think "linux distributions are dangerous" is the wrong conclusion. the right one is to treat each distribution based on their own security practices, and not "linux" as a whole. one distro's bad practices doesn't make others unsafe any more than one distribution's good practices make other safe.
- sethhochberg 2mo agoThe real takeaway for projects and companies should be that someone having historically behaved in a logical and responsible way doesn’t guarantee that they’ll continue to do that for forever. Good security architecture has circuit breakers, even for people who are generally high-trust.
- lenerdenator 2mo agoI wouldn't say that there's an organized attempt to "paint Linux distros as dangerous". It's just what happens when you have people being people (as we see here) and there are structural vulnerabilities to software supply chains. It's a juicy target, and it's being exploited. We can either learn from it or continue to suffer. This isn't even new. Hell, I remember when Linux Mint was hacked a decade or more ago. They compromised the forums, the disk image downloads, the whole shebang. I haven't used it since.
- iririririr 2mo agostop trying to make AUR sound like a place that can be compromised. it's literary a tetanus ridden landfill, by design! it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work) the fact that idiots (in the original sense of the word in Greek) made automatic installers that fools novices to think those are vetted distro packages doesn't make it so.
- fhn 2mo ago"should have" "could have". Geez. This was malicious. Take legal action already!
- account42 2mo agoTo what end? Not every dispute needs to go to court. In this case the guy was already kicked out of the project and now publicly shamed.
- aforwardslash 2mo agoI had no idea mandriva/openmandriva still existed. I still have a mandrake cd somewhere, mostly because I cannot seem to be able to depart from physical media :)
- deeprack4sure 2mo agoI feel for the maintaners. There is a push and pull here on OSS. However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam. Because Im not dependent on PRs from randos this doesnt really matter to me. I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host. And go underground. Or decide whether the juice is any longer worth the squeeze. In my mind its not unless its off the internet. You may skate today, tomorrow you are completely screwed.
- teekert 2mo agoSlop PRs are just spam, we learned to deal with spam on email, we'll learn to deal with this as well. Fwiw, I don't think it's an "AI" problem, is a knowledge and respect problem from the people that have their agents dump code on FOSS projects.
- account42 2mo agoEmail spam takes at least an order of magnitude less effort to identify.
- 0123456789ABCDE 2mo agointeresting that i already had blocked github.com/davidebeatrici unfortunately i did not add a note at the time
- BSDobelix 2mo agoIt's kind of problematic that hes part of mumble, but especially SoftEtherVPN. Bravo, Davide, for erasing your trust score to zero. And for what? Was it worth it?
- lrvick 2mo agoIn the Stagex Linux distribution it is not possible for any single person to release anything. We require multiple independent review and reproduction signatures from the maintainer team. We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.
- shevy-java 2mo agoI can not evaluate the claims made, but even if I am lenient and assume it is all true, to me it is still strange how a distribution becomes so dependent on a single person or provider. I can't help but wonder how other distributions would have handled that; Gentoo would probably not have ended in a similar situation, debian probably neither. And mind you - that's only if I evaluate the claims made at face value. I also can't help but feel that there are some missing steps here. Sure, IRC roid-raging happened in the past, see #freenode, and people are strange in general, but even then it really reads oddly to me, almost as if "I trusted that scammer from Nigeria with my money because the emails were so convincing".
- ThePowerOfFuet 2mo agoNot deleting a comment like this says a lot about the project, none of which is good. The moderator replied, the commenter replied, yet the comment remains. https://forum.openmandriva.org/t/statement-regarding-attempted-distribution-sabotage/8997/15 https://forum.openmandriva.org/t/statement-regarding-attempt... Shameful.