| ▲ | drnick1 2 hours ago |
| Another win for the Linux security model (software installed and updated manually from vetted repos only). |
|
| ▲ | voidUpdate 2 minutes ago | parent | next [-] |
| sudo dkpg -i FileYouDownloadedFromAnywhere.deb |
|
| ▲ | gblargg an hour ago | parent | prev | next [-] |
| Wait, you're saying a monitor can just advertise a URL over the video connection for its driver and then Windows will blindly install it, without user confirmation? I thought that LG had submitted these "drivers" (adware) to Microsoft and they approved it. |
| |
| ▲ | stkdump 40 minutes ago | parent | next [-] | | I think the point is that: 1. Yes Windows must have "approved" the drivers 2. Windows Update runs automatically and not (usually) manually 3. Automatic update can't even be disabled, only manually postponed a bit At least 2 and 3 are different on virtually every Linux distro. Also, I find it very unlikely that they would accept such behavior. To give MS the benefit of the doubt here, now that this happened and has been reported on they might decide to enforce stricter rules on manufacturers in the future. But as a Windows user you don't have a choice in case you don't like how they decide and how their decisions might change again later. | | |
| ▲ | dmos62 28 minutes ago | parent [-] | | https://github.com/raphire/win11debloat This has an option to disable downloading of auxiliary apps when a device is connected. Yes, it's a Windows Update thing. > Prevent Windows from auto-installing device companion apps, like LG Monitor App, Alienware Command Center and more. |
| |
| ▲ | bayindirh an hour ago | parent | prev | next [-] | | I believe you register your device with Microsoft so Windows can automatically obtain and install drivers for them when they are plugged in. What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware. | |
| ▲ | ssl-3 44 minutes ago | parent | prev [-] | | Eh? No. It's just a device attached to a computer. But in a Plug-and-Play world, its addition is noticed by the operating system -- as has been normal for decades. Microsoft's Windows operating system sees this new hardware ID and then goes forth to install whatever-the-fuck software it associates with that identification, presumably as a service to the user. (Did Microsoft approve it? Dunno. I'm just over hear eating popcorn.) |
|
|
| ▲ | delta_p_delta_x 36 minutes ago | parent | prev | next [-] |
| > Another win for the Linux security model I swear, OSs have become sports teams. Linux's 'security model’ has plenty of holes. The very fact the kernel and much of its user-mode is written in C almost guarantees that its security model is worthless. The Linux ecosystem operates on trust and respect that can and has been easily abused by bad actors to provide supply-chain pwnage. There have been so many zero-click local privilege escalation CVEs I've lost track. Arch Linux AUR malware: https://lists.archlinux.org/archives/list/aur-general@lists.... |
| |
| ▲ | silver_silver 28 minutes ago | parent | next [-] | | AUR is an effectively unmoderated user repo. It’s not Arch Linux’s core repository, nor is it enabled by default or indeed even possible to use without manual downloads from outside the package manager. | |
| ▲ | opan 27 minutes ago | parent | prev [-] | | I think you can probably find a better example, even if less recent. The AUR is unofficial and not properly vetted in the same way as the actual Arch repos, Debian repos, etc. |
|
|
| ▲ | krige an hour ago | parent | prev [-] |
| Surely you mean Linux security model (not relevant enough to be targeted by big tech)? |
| |
| ▲ | dns_snek an hour ago | parent [-] | | It's not a weakness that they targeted and exploited, it's a feature that was purposefully implemented by Microsoft. |
|