Several sites are covering an incident affecting Raspberry Pi OS deployments since last week. Quietly, without disclosure or warning, a package added a Microsoft repository and OpenPGP key to the system. The latter effectively gives the former full root access, in principle, to the whole system. The former checks in with Microsoft's servers any time APT refreshes its cache.
$ grep -i pretty /etc/os-release
PRETTY_NAME="Raspbian GNU/Linux 10 (buster)"How to know if you're affected/infected already:
$ cat /etc/apt/sources.list.d/vscode.list
### THIS FILE IS AUTOMATICALLY CONFIGURED ###
# You may comment out this entry, but any other modifications may be lost.
deb [arch=amd64,arm64,armhf] http://packages.microsoft.com/repos/code
stable main
Issue has been taken with both what has been done and how it has been deployed. The official explanation is, for now, that resource hog Visual Studio was to be made available by default on the Raspberry Pi for development for their first entry into microcontrollers, the Raspberry Pi Pico. This is in spite of the established presence of many light weight editors and IDEs alredy[sic] available through vetted repositories. Not to mention the package could have been added to the established, vetted repositories. Threads on the topic over at the Raspberry Pi Forum are quickly locked by moderators and then deleted.
(Score: 3, Insightful) by Anonymous Coward on Friday February 05 2021, @04:27AM (3 children)
You know it's quality when dissenting posts get locked and deleted.
I believe that's how the Arch Linux forums introduced systemd.
(Score: 2, Insightful) by Eratosthenes on Friday February 05 2021, @07:18AM (2 children)
Raspberry Pi has never really been an open-source operation. They only used free software, until they got big enough to attract the major sharks, like Microsoft. So now, we will have an ARM version of Windows? Even though it has been repeatedly proven that such cannot be? And then, we will license, and incense, and recapitulate, the Windo$e operating system, or no education will take place. Raspberry was a sucker plant? A Siren? An open source honey pot? Say it ain't so, Raspberry Foundation! Those poor bastards!!! Will be reduced to taking pictures of snowflakes, in a year or two.
(Score: 2) by hendrikboom on Friday February 05 2021, @08:56PM
Isn't there already an ARM version of Windows?
And isn't it as locked-down as Microsoft can make it?
(Score: 4, Insightful) by everdred on Friday February 05 2021, @11:42PM
Sort of reminds me of the OLPC project, when they started shipping Windows XP machines.