Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not just educational desktop environments: this issue affects Raspberry Pi OS Lite which is the primary operating system for Raspberry Pi's used in embedded and IoT applications. Some of which have automatic updates (called "unattended upgrades" in Debian parlance).


But this doesn't grant remote access to your system, and it's not like Microsoft will start shipping replacements of core packages over this repo.


Technically it does grant another avenue of supply chain attack... but if Microsoft run mirrors are being compromised then we probably have much bigger issues than some raspberry pis.


Considering the damage that can be done by botnets like Mirai, Raspberry Pis might be exactly what we should be worrting about.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: