7 ms·
This guy is actually perfectly right. Google doesn't do thing like that by accident. I'm glad there are some sharp guys around to disclose such potentially mali
by BRG_12 11y ago
This guy is actually perfectly right. Google doesn't do thing like that by accident. I'm glad there are some sharp guys around to disclose such potentially malicious behavior.
- rockdoe 11y agoDo what by accident? Of course the intent was to include the blob. If Debian wants to get rid of it it should patch Chromium or request it to be made configurable (which is what happened). But the tinfoil hattery is completely baseless.
- buster 11y agoBut you do understand that Chromium is supposed to be open source, right? So, if the intent was to include a binary, closed source blob into an open source project, that could be called malicious.
- rockdoe 11y agoIt was very much the intent: https://code.google.com/p/chromium/issues/detail?id=491435 https://code.google.com/p/chromium/issues/detail?id=491435 Chromium is and has always been an open source project in name only.
- marrs 11y agoYou mean, you couldn't compile it from source, modify the source code and distribute your modifications freely to others?
- fluidcruft 11y agoNo, he means Chromium (like Android) in practice are read-only, hostile projects that respond only to Google's needs. Yes, you are free to create a fork. In reality, it's nearly impossible to keep up with Google's development pace and their behavior of dumping huge changesets and lack of documentation and communication wears everyone out. If you have some exposure to biology/ecology you'll recognize the behavior as very effective at killing off diversity in ecosystems. It's like trying to co-exist on a lake with someone that keeps deliberately causing giant algal blooms.
- jsight 11y agoOh ok. So it would be more open source if the upstream vendor contributed less.
- rockdoe 11y agoWhich part of "their behavior of dumping huge changesets and lack of documentation and communication wears everyone out." is not clear to you?
- magicalist 11y ago> No, he means Chromium (like Android) in practice are read-only, hostile projects that respond only to Google's needs. Huh? You've obviously never involved yourself in Chromium development. It's easy to get started and to stay up to date. As with all massive projects it takes work to do so, but no more so than any of the other open source browsers.
- pessimizer 11y agoHave you had a lot of experience in keeping your Chromium fork up to date?
- strcat 11y agoUnlike Android, Chromium is mostly developed in the open. As someone who has contributed to both projects, I wouldn't say Chromium is any less welcoming to contributors than Firefox. Mozilla is a lot better at presenting themselves in a positive light. Firefox even has similar automated downloaded of binary blobs like the EME plugin.
- rockdoe 11y ago>As someone who has contributed to both projects, I wouldn't say Chromium is any less welcoming to contributors than Firefox. You're far more likely to have hidden discussions about features or get patches obsolete due to code drops out of the blue when trying to upstream to Chromium. >Firefox even has similar automated downloaded of binary blobs like the EME plugin. Mozilla's EME stuff was widely discussed, announced in advance, and coordinated with distros. Not quite in the same league as this.
- mavhc 11y agoOpen source vs FLOSS vs Open development vs Open leadership Chromium seems more open development than Android anyway.
- dtech 11y agoEven if malice instead of incompetence is involved, it goes pretty far to call Chromium a "rootkit-downloader" just because it downloads a binary blob. It could theoretically be a rootkit, but without any evidence to support it this is like calling someone a murderer because he went to the same high school as a murderer.
- morganvachon 11y ago> without any evidence to support it this is like calling someone a murderer because he went to the same high school as a murderer. That's a pretty flawed analogy. If you're going to examine it from a criminal act point of view, let's really look at it that way. If installing a rootkit is equivalent to premeditated murder, then the murderer must have motive, means, and opportunity. Let's take Sony as a good example of a company guilty of installing a rootkit. Motive: Prevent unauthorized copying of their music CDs. Means: Rootkit is embedded in the audio CD and uses Windows' Autoplay feature to install itself. Opportunity: They didn't disclose this rootkit so anyone who bought a Sony audio CD during that era was vulnerable. Now, let's look at what we know about this Chromium binary blob silent install (note I'm not calling it a rootkit, as I agree with you that's taking it a bit far, but it would theoretically be possible to install one via the same method). Motive: Google wants to put the same always-listening "feature" on Chromium installs as well as plain old Chrome. Means: Google writes and publishes the Chromium source code. Opportunity: Just guessing here, but Google releases this change without announcing it (otherwise why didn't the Debian packagers see it right away?). Now, once again I'm in agreement with you that calling this a rootkit downloader is a bit much. But what if it had actually been a rootkit, inserted by Google either intentionally (I don't trust them, but honestly why would they do something that nefarious?), or without their knowledge or consent (which would mean they are compromised by an outside actor). That is why this is such a big deal, and kudos to the Debian team for finding it. It also bothers me that this binary blob, while not actually a rootkit, did have the ability to listen to the computer's microphone 24/7 (yes, that is a "feature" as it is part of Google Now), and can't be audited because there is no publicly available source code. That's quite a security hole; I recall discussing all kinds of financial and personal matters with my wife right in front of our computers. Thankfully they are both desktop machines without built in microphones, but many people these days use laptops as their main computer. To sum up, I don't like it and I think it's a shitty thing for Google to do. Whether it was intended to be a silent install instead of public knowledge, or just a major gaffe, remains to be seen.