Ventoy: Remove BLOBs from the Source Tree
github.com
github.com
Ventoy developer longpanda offers tools for injection into Linux and Windows ISOs, which work with the Ventoy injection plugin, https://news.ycombinator.com/item?id=38691857
> Deepin is a distribution developed in Wuhan, China by Deepin Technology. Its homepage proclaims it "the top Linux distribution from China" ... The extensive EULA is uncommon for the Linux space, and the privacy policy goes into some detail about the types of information they collect – not just browser history, but information on when you use your computer and the applications installed on your system.
If you mean to just highlight the association with Deepin it doesn't need to be guised as a question.
> It would be much appreciated if you want to make a small donation to support my work! > Alipay, WeChat Pay, PayPal and Bitcoin are available for donation. You can choose any of them.
So far I've never used Ventoy due to these issues. The concept sounds great though.
A simple virus could easily backdoor every binary on the system which built the file, rince and repeat.
Before anyone says that Linux virus do not exist, I have written a handful, as I'm sure many others have. Do not assume lack of observation to be confirmation of your view.
The second I wrote was attempting to exploit the trust that erlang VM's have with each other. I have rewritten a few in various BEAM based languages, this was to give evidence to management that security/protections should be put in place for erlang clustering (rabbitmq, HA erlang, etc).
Another was for working for a large north american linux vendors product security group, In an effort to know ones enemy and the effort involved in some of the 'in-the-field' backdoors that were found. In this case, I was reproducing the "virus/RAT" (I use that term loosely) that contained dirtycow exploit primitive in the wild. I also reversed/reproduced/(exploited ?) their exploitable C&C infrastructure. This information was handed over to the law enforcement and I've never heard any more about it.
Each virus had its own reason, none of them escaped my demonstrations.
that sounds extremely interesting and useful. specially now with the elixir renascence
or that you've genuinely never come across one?
I mean, just stop by reddit!
On one hand, it integrates a lot of open source components, but there is enough custom stuff going on that I’m concerned.
Look how it boots a Linux live cd… Initramfs injection is well used — perfect for malware.
For security, I always recommend Burning an ISO into a physical optical disc. Check the ISO MD5 before burning. No thumbdrives.
Then pray god your Government only aproves sales of backdoored hardware where you live. I recommend at least disabling (pulling out) the build-in Network cards (yes, wifi/bt too) and buying usb replacements.
"concerning"
No where near the ergonomics as far as I can tell, but with containers, there's been an effort to make bootable containers. I seem to remember there being some other options (I wanna say like Wyvern or something like that was one but not finding it), but the big obvious effort is bootc. https://containers.github.io/bootable/projects.html . 38d old thread: https://news.ycombinator.com/item?id=40289120
https://www.iodd.shop/IODD-ST400-USB-30-External-Encrypted-H...
I love using my IODD in "dual-mode" with Clonezilla. It exposes a USB-DVD drive with an emulated Clonezilla DVD in it as well as its' HDD storage so I can dump an image right to the hard drive.
(Bonus points: I can then have Clonezilla bundle me a clonezilla-iso package of my captured image, and save it back into the ISO folder to boot from later!)
But also, I'm insanely frustrated that (1) Google doesn't allow USB Gadget mode to do this from stock Android (2) the app that appeared to work for LineageOS/rooted devices is abandonware.
There's no good reason why your phone can't serve up ISOs with gadget mode.
I already travel with my ancient Pixel 3a as a backup (which has come in handy, clumsy me). It would be slick to have that as a portable ISO host, and backup phone. (Ignore the USB2 USB-C port, it's fine.)
...and runs on the Pixel 3a: https://devices.ubuntu-touch.io/device/sargo/
It's using a Raspberry Pi Zero to emulate a USB CD-ROM. A menu on the device allows you to choose an ISO to boot from.
Has it involved into something more complex? It seems odd to complain about binary blobs in something that is meant to be a tool for aggregating pre-existing binary boot media into a single image.
Personally, I don't and use stuff like Rufus[1] instead.
You can add arbitrary netboot images, but I'm not actually sure how much it can do with no network at all.
i am still waiting for an ergonomic way to have a persistent usb install of a linux distro, which does not kill the flash storage over time. till then, i got similar levels of trust of the tool as i do with using windows.
FWIW, I think you mean `dd`.