I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.

  • Todd Bonzalez@lemm.ee
    ·
    1 day ago

    Anyone who wants to fix this can help fix it, but people are just making demands of an unpaid maintainer. The devs can run this project the way they want to. If you don't like it, don't use Ventoy.

    The people comparing this to the xz exploit are out of line. xz was a library that was deeply embedded in a lot of software. Ventoy is an IT tool used to boot live OSes. Not even remotely the same attack surface.

    Blobs in the source tree are not ideal, but people need to pick their battles.

    • Lemongrab@lemmy.one
      ·
      1 day ago

      From what others have said: The blobs violate GPL because they are taken from other FOSS project but the changes Ventoy makes are not viewable.

    • tetris11@lemmy.ml
      ·
      1 day ago

      Little did they know that Patches the Cat bit through their LAN lines and actually increased the cost of their communication.

  • Mikelius@lemmy.ml
    ·
    2 days ago

    Glad it's getting a little more light. Been trying to tell people this for a few years now lol. It's the reason I've stayed away from it since first learning of the tool and looking at the "source code".

  • PowerCrazy@lemmy.ml
    ·
    2 days ago

    Hey guys open source is great you can look at all the code and therefore there are no security backdoors etc. Also here are a bunch of pre-compiled blobs in the repo, don't worry about those, but they are required to run the program.

  • monovergent@lemmy.ml
    ·
    2 days ago

    Makes me wonder how far the closest alternative, glim, could be upgraded to match Ventoy given the confines of GRUB.

    Someone had mentioned that Fedora fails to verify when booting from Ventoy. Now I'm thinking if I could dd the media loaded via Ventoy and compare with an original copy to see what changed.

  • ulterno@lemmy.kde.social
    ·
    2 days ago

    I like multiboot. Used it back when I used Windows.
    The Ventoy advertisements on Reddit looked too suspicious, so I never checked it out.

  • LalSalaamComrade@lemmy.ml
    ·
    2 days ago

    Thank you for sharing this. I remember using Ventoy quite often back when I was still on Windows. I'll be sticking with the good old dd command.

    • Quail4789@lemmy.ml
      ·
      2 days ago

      Yep, some people these are saying just 7 of the 150 binaries don't have source or build info. Yeah, one binary is enough to do all the evil in the world, not that other binaries support reproducible builds anyway.