Thoughts on Technology

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 27 November 2010

Ubuntu PPA Problem - Reason for Concern?

Posted on 10:15 by Unknown
With the release of Ubuntu 9.10 late last year Canonical introduced PPAs, which is short for Personal Package Archives. A PPA allows anyone that has signed the Ubuntu Code of Conduct to easily distribute software they have packaged to Ubuntu users. This revolutionary idea allows those who do not have the capability to establish their own repository to easily provide package updates to their users. Want the latest version of Openshot or PiTiVi? Then simply add a PPA to your system that packages up to date versions of these softwares and you will be set to go!

The problem with this system you ask? There is namely one issue: Canonical does not review any of the packages that are uploaded to PPAs. Because of this adding software from various PPAs wily nilly in reality is more dangerous than installing software on Windows. I say this because not only are you giving root access to the software upon installation, but also every time you run a system update from then after. Meaning even if a PPA provides trusted packages at first, this could change later on.

While it has not happened yet (as far as I am aware), I feel it is only a matter of time before some form of malicious code makes its way into a PPA that is used large scale. If you are comfortable with having software installed on your system from many different sources - that is your own choice (one of the many great things about FOSS). However, if you always need the latest up to date software maybe it is worth considering a rolling release distro such as LMDE or Chakra.

What is your take on this? Am I just blowing hot air and worrying for nothing or could having piles of PPAs on your system cause a potential risk down the line?

~Jeff Hoogland
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in open source, rant, software, ubuntu | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • HOWTO: Watch Netflix on Bodhi Linux
    Not being able to utilize the Netflix video streaming service has been an issue on the Linux desktop for the past few years. This is due to...
  • Blackboard - No Linux for Online Education
    In addition to being a Linux Advocate and working 40+ hours a week I am also a full time student. Due to schedule constraints I often take ...
  • HOWTO: Ubuntu Linux on T101MT
    I wrote a HOWTO for getting Linux working on the T91MT a couple months back and as I mentioned here I ended up changing to the slightly la...
  • HOWTO: Test E18, EFL 1.8.0, and Terminology 0.4.0 on Bodhi Linux
    As of this past weekend the testing builds of the Enlightenment window manager DR18 (E18 for short) are in the Bodhi Linux testing repositor...
  • N900 Faster Application Manager - Review
    If you have ever installed an application on an N900 using the default application manager you know that while it is functional it is not t...
  • HOWTO: Perfect Terran Proxy Build Order - Starcraft 2
    Today we take a short break from our normal broadcasting to talk about a bit of gaming strategy. In Starcraft 2 a "proxy" means ...
  • Pearson Education - You will NOT use Linux
    Summer is winding down and fall semesters are starting all around the country. My girlfriend started classes this week and one of her onlin...
  • Team Work in Open Source Projects
    What makes a great open source project? Well, first off you have to have an idea. Then you need to execute said idea. Just over a year ago I...
  • Bigger is Better... Right?
    It appears the mantra of "bigger is better" has gripped developers of the late as the handsets we see keep getting larger and larg...
  • HOWTO: Unlock your AT&T Tilt for all Networks
    Something I hate more than anything else in the world is a software lock on hardware I own. If I bought something I should have the right to...

Categories

  • 3g modem
  • adobe
  • android
  • appeal
  • apple
  • arm
  • art
  • asus tablet
  • benchmark
  • bodhi
  • bordeaux
  • cedega
  • chakra
  • chrome os
  • chromebook
  • cockatrice
  • codeweavers
  • comic
  • cricket wireless
  • crysis
  • cxgames
  • debian
  • dell duo
  • diablo3
  • distro review
  • dtf
  • e18
  • eandora
  • eccess
  • elementary
  • elive
  • enlightenment
  • fedora
  • firefox
  • gaming
  • genesi
  • gnome
  • google
  • google chrome
  • google wave
  • handheld device
  • hardware
  • helios
  • howto
  • html5
  • ideapad
  • interview
  • ipad
  • jolicloud
  • kde
  • l4d2
  • laptops
  • lenovo
  • linux
  • lxde
  • macbook
  • math
  • maxima
  • media
  • meego
  • milestone
  • mint
  • mir
  • mk802
  • moblin
  • n900
  • netflix
  • nexus 7
  • nvidia
  • open pandora
  • open source
  • opengl
  • opera
  • operating systems
  • palm
  • phones
  • promotion
  • python
  • qt
  • rant
  • raspberry pi
  • reviews
  • sabayon
  • software
  • source games
  • spotlight
  • sprint
  • starcraft2
  • steam
  • t-mobile
  • tutorial
  • ubuntu
  • unigine
  • unity
  • wayland
  • web application
  • windows
  • windows 7
  • wine
  • wxmaxima
  • xfce

Blog Archive

  • ►  2013 (20)
    • ►  December (1)
    • ►  November (1)
    • ►  September (1)
    • ►  June (1)
    • ►  May (2)
    • ►  March (2)
    • ►  February (3)
    • ►  January (9)
  • ►  2012 (57)
    • ►  December (5)
    • ►  November (4)
    • ►  October (2)
    • ►  September (1)
    • ►  August (4)
    • ►  July (9)
    • ►  June (4)
    • ►  May (4)
    • ►  April (1)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2011 (107)
    • ►  December (8)
    • ►  November (8)
    • ►  October (5)
    • ►  September (14)
    • ►  August (9)
    • ►  July (8)
    • ►  June (7)
    • ►  May (10)
    • ►  April (9)
    • ►  March (13)
    • ►  February (9)
    • ►  January (7)
  • ▼  2010 (122)
    • ►  December (10)
    • ▼  November (8)
      • Ubuntu PPA Problem - Reason for Concern?
      • T-Mobile "4g" Failure
      • Wayland VS X - Some Perspectives
      • Announcing Bodhi Linux
      • Silence is greater than Misinformation
      • HOWTO: Manually set GDM Background and GTK Theme
      • Fusion Linux 14 - Distro Review
      • I am a Linux Geek (and Proud of it!)
    • ►  October (10)
    • ►  September (14)
    • ►  August (17)
    • ►  July (10)
    • ►  June (9)
    • ►  May (14)
    • ►  April (8)
    • ►  March (7)
    • ►  February (7)
    • ►  January (8)
  • ►  2009 (27)
    • ►  December (10)
    • ►  November (7)
    • ►  October (10)
Powered by Blogger.

About Me

Unknown
View my complete profile