| The tone was inflammatory but the sentiment is valid. Quoting: Since no one really know which binaries have been downloaded there and what they actually do, and since it cannot be excluded that it was actually executed, such systems are basically to be considered compromised A closed source binary being silently downloaded and executed without explicit action by the user or notification to the same is a security incident. Many people are used to it because of all the training received by the "Java Auto Update", "Google Update Helper" and similar software receiving blank permission to monitor, download and execute closed source software with the same permission as the logged in user. Despite of that a person that goes to the lengths of using Debian (instead of Ubuntu) and Chromium instead of Chrome certainly expects more from their sources than to allow this kind of behaviour. It is a security incident and should be treated as one both by Debian and by the community in general. |
Whereas source code being downloaded, compiled and run is not? Or a script being downloaded and run?