Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.
Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.
But package managers can also have lookalike names. Npm and pip has had a few famous misspelled common packages that contained malware instead. Those are more open than apt or the big app stores but even on Google play you will find tons of lookalikes.
This whole incident just shows you should never just search for anything by name and pick the first good looking result. You really have to verify the source regardless of which search engine you are using. What I very much dislike is companies who refer to their own app in the app store only by name and then you when you search you get 10 results which all look equally shady. And because they outsourced the app development the publisher doesn't even match. Place a god damn link or show the unique package name on your websitr instead.
You know how Google & Firefox could easily help fix this? List their browsers in the Mac and Windows Store.
The interface for this is "start nice gui front end, type firefox into search bar, select firefox package, click install"
It's tricky to get win32 apps in general into it, too.
For general win32 apps I do think the situation has improved since I last looked.
2. You install "this" with your package manager
3. Even if the "this" installed wasn't the "this" you read about in your browser, it still came from your package manager repos, which you could consider safe, and you'll be able to uninstall it cleanly.
Then I look at the Windows Store and weep.
I will admit that Chrome/Chromium is one of the few things you can't easily get from the repos, on Ubuntu at least.
The security of the package repository system falls down when people add apt signing keys that are untrusted/unverified, which is what happens when you add a ppa in Ubuntu.
We're sort of in a loop here -- how can I know what is the official Chromium website?
Yeah, unfortunately that's what verifying the legitimacy of the chromium-team Ubuntu ppa requires...
Anyway, there are two quick ways I found:
* Go to chrome://settings/help and see the link to Chromium.org (but obviously this doesn't work if you don't have Chrome already)
* At the bottom of google.com/chrome there is a link to Chromium.org
Googling debian google chrome results in instructions for getting chrome on debian.
I have 3 different distros installed on 3 different computers. Chrome is listed on all app searches.
Yes. I know. I'm not picking on debian specifically here, fedora's dnf doesn't help you install chrome either.
My point is rather the following: The GP asserts that the way to find (and subsequently install) software is "apt search `software`" and that way breaks down on exactly the piece of software that the article is about. You have to google instructions and then install either the .deb or add googles repo. And that's where the attacker could just as well insert an ad pointing you to a malicious repo. Just as the attacker currently points people to a malicious download. So the GPs solution isn't a solution at all. Not to this problem.
Unfortunately Google Chrome is a bad example here as it's not available in most repos (since it's closed source).
That’s a bold statement to make, especially since a single piece of malicious software is sufficient. And yes, I want chrome. I need chrome. I need to test stuff on chrome.
Chromium is available in the repos.
take a look at https://appget.net if you use windows.
I have my doubts that any Linux distribution is capable of auditing every line of every package they distribute, so I think the relative lack of malware on Linux (and possibly MacOS as well) may not actually be caused the specific method of distribution.
I don't agree. If you search for "chrome" or "firefox", you will get a page full of spammy apps that are anything but what you searched for.
Linux distributions probably don't audit every single line of code in the packages, however this is code written by trusted developers that is mandated to be open source and distributed through official channels.
Getting malware into the package repositories would be very difficult, but it seems that getting a fake Google ad on Bing is very easy, so in my opinion the distribution method makes a big difference.
You depend on your distro mantainers to package what you need to install. If it isn't packaged, best case scenario is you get a tarball, which is already too hard for 99% of computer users. Snaps and Flatpaks are still too unpolished.
Getting all your user applications (DAW, IDE, etc) from your OS developer (instead of getting it from the application developer) is also against the sentiment of freedom that so many Linux users preach.
There are many alternative repositories for essentially all distorts today; snaps and flatpaks are indeed not yet polished enough, but they are much better and easier for 99% of users than tarballs, so calling tarballs a “best case scenario” is, in my opinion, wrong.
You were complaining tarballs are the “best case” and are not good enough because they’re too hard for regular users.
PPA is as easy as windows downloads; it updates the same way as the main system unlike windows; and it always go through ununtu’s Servers which makes it somewhat more monitorable. But that’s a new discussion.