I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.
n2burns ( @n2burns@lemmy.ca ) 57•6 months agoI too wish the developer would respond, but I don’t think this is the catastrophe people are making it out to be. One comment seems to explain why these binaries are included:
Because ventoy supports shim, and by extension secure boot, these files needs to come from a signed Linux distro. In this case they are taken from Fedora releases, and OpenSUSE apparently, as they publish shim binaries and grub binaries signed by their certificate.
infeeeee ( @infeeeee@lemm.ee ) 8•6 months agoIt sounds to me as a documentation issue, as the next comment says, simply including a
wget
script should solve this. ReversalHatchery ( @ReversalHatchery@beehaw.org ) English4•6 months agothat’s only a few files out of the 153
PowerCrazy ( @PowerCrazy@lemmy.ml ) English48•6 months agoHey guys open source is great you can look at all the code and therefore there are no security backdoors etc. Also here are a bunch of pre-compiled blobs in the repo, don’t worry about those, but they are required to run the program.
Snot Flickerman ( @SnotFlickerman@lemmy.blahaj.zone ) English15•6 months ago delirious_owl ( @delirious_owl@discuss.online ) 14•6 months agoRight, the fact that it’s open is the reason this came to light, and we’re having this discussion
ulkesh ( @ulkesh@beehaw.org ) English4•6 months agoExactly. Acting like this is an “ah-ha, see?!!” moment when this is exactly what open source is designed for. That’s like saying global warming is a hoax because “oh look it’s snowing”.
PowerCrazy ( @PowerCrazy@lemmy.ml ) English2•6 months agoThis isn’t a knock against opensource programming, but there shouldn’t ever be precompiled blobs in the repo unless they are the official builds for the various OS’s and if you want to build from source, the pre-compiled blobs shouldn’t be part of that, otherwise you can’t really claim you are opensource.
ulkesh ( @ulkesh@beehaw.org ) English1•6 months agoYes, and that’s what is being called out here. But your original comment makes it sound like you are advocating for closed source software and that somehow open source software is bad.
This is the system working as intended. When potential issues arise, it’s openly discussed and ideally resolved. And if not, trust is lost and people will stop using it.
PowerCrazy ( @PowerCrazy@lemmy.ml ) English1•6 months agoI don’t know about the history of the project, but it sounds like those blobs have been there for quite some time. When in reality, the PR that added the blobs in the first place shouldn’t ever have been approved.
Actually just checked 3+ years.
delirious_owl ( @delirious_owl@discuss.online ) 1•6 months agoWell, it is an “ah-ha, see!” moment, because it shows the benefit of open source.
Its more like pointing at the absence of a glacier on a mountaintop and saying “yep, see, climate change does exist”
ulkesh ( @ulkesh@beehaw.org ) English1•6 months agoI was referring to the commenter and how it read to me :) But agreed, what you said, too.
Mikelius ( @Mikelius@lemmy.ml ) 30•6 months agoGlad it’s getting a little more light. Been trying to tell people this for a few years now lol. It’s the reason I’ve stayed away from it since first learning of the tool and looking at the “source code”.
delirious_owl ( @delirious_owl@discuss.online ) 23•6 months agoWtf is ventoy and why is nobody explaining it
thingsiplay ( @thingsiplay@beehaw.org ) 25•6 months agoI used Ventoy (its still on my USB stick). Its actually a pretty cool concept. Normally without Ventoy, you would flash your Linux distribution on the USB stick. And then you can boot from it, right?
Ventoy instead allows you to have a folder where you put an ISO without flashing it, and then you can boot from it by selecting in the menu. You just need to flash Ventoy once, as the base system, then you can put as many ISO files into that directory. I tested it and have 7 different Linux distributions (ranging from 1 GB to 4 GB variants) on the same USB stick, and I can boot any of them without flashing again. Replacing ISO is extremely easy, just delete it and copy a new one. Filenames does not matter, anything can be found.
Moah ( @Moah@lemmy.blahaj.zone ) 18•6 months agoWtf is a BLOB and why is nobody explaining it
Tamo240 ( @Tamo240@programming.dev ) 20•6 months agoBinary Large OBject
Basically any binary file, often objected to in open source repos because of the lack of source and ‘openness’. See also the recent xz backdoor.
thingsiplay ( @thingsiplay@beehaw.org ) 8•6 months ago spikespaz ( @spikespaz@programming.dev ) 3•6 months agoBecause you can look it up.
refalo ( @refalo@programming.dev ) 0•6 months agobecause search engines exist
Wtf is search engines and why is no one explaining it
namingthingsiseasy ( @namingthingsiseasy@programming.dev ) 0•6 months agoSearch engines are websites that people used to go to in order to get helpful information. These days, they just spam out a bunch of SEO garbage, AI-generated bullshit, and ads.
Google, probably
thepiguy ( @thepiguy@lemmy.ml ) 23•6 months agoAs a wise one once said: “Talk is cheap, send patches”
tetris11 ( @tetris11@lemmy.ml ) 4•6 months agoLittle did they know that Patches the Cat bit through their LAN lines and actually increased the cost of their communication.
monovergent 🛠️ ( @monovergent@lemmy.ml ) 21•6 months agoMakes me wonder how far the closest alternative, glim, could be upgraded to match Ventoy given the confines of GRUB.
Someone had mentioned that Fedora fails to verify when booting from Ventoy. Now I’m thinking if I could dd the media loaded via Ventoy and compare with an original copy to see what changed.
Snot Flickerman ( @SnotFlickerman@lemmy.blahaj.zone ) English12•6 months agoAll my laziness about not checking it out has come to fruition. Now I simply don’t have to, because this is sketch as fuck until it is handled.
sorter_plainview ( @sorter_plainview@lemmy.today ) 11•6 months agoThis is a bit absurd. I really don’t think this is as serious as some comments say. Also there is a comment from AUR package manager which explains more details. . And even the blobs in the first post there are source and build instructions in their respective folder.
thingsiplay ( @thingsiplay@beehaw.org ) 12•6 months agoThat linked reply doesn’t explain anything. It just says “bro trust him”. Just because you and the AUR maintainer says its trustful, does not make it clear whats behind the binary blobs. It doesn’t matter what anyone says, if we can’t verify. In my opinion, its absurd calling others absurd for not trusting the word of others.
- ulterno ( @ulterno@lemmy.kde.social ) English6•6 months ago
I like multiboot. Used it back when I used Windows.
The Ventoy advertisements on Reddit looked too suspicious, so I never checked it out. jsomae ( @jsomae@lemmy.ml ) 6•6 months agoWhat does BLOB stand for?
pokexpert30 ( @pokexpert30@lemmy.pussthecat.org ) 5•6 months agoI just wish it had a real alternative. GRUB on USB doesnt support as much distros or windows.
Rentlar ( @Rentlar@lemmy.ca ) 3•6 months agoIt’s a useful tool, but there is a security concern for anything not fully open source. You will have to weigh your risk factors, I doubt that it’s any problem for most consumers or distro hoppers.
Best to keep an eye in case any new contributers arrive suddenly…