Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.kde.social
kde·KDEbyBro666

WARNING: Global themes and widgets created by 3rd party developers for Plasma can and will run arbitrary code. You are encouraged to exercise extreme caution when using these products.

A user has had a bad experience installing a global theme on Plasma and lost personal data.

Global themes do not only change the look of Plasma, but also the behavior. To do this they run code, and this code can be faulty, as in the case mentioned above. The same goes for widgets and plasmoids.

We are calling on the community to help us locate and quarantine defective software by using the "Report" buttons available on each item in the KDE Store.

Please see this linked image to locate them.

Meanwhile, KDE is taking measures to properly warn users before each download and we are also putting in place ways of auditing and curating what is uploaded to the KDE store.

Nevertheless, this will take time and resources. We recommend all users to be careful when installing and running software not provided directly by KDE or your distros.

And remember to report any faulty products you find!

View original on lemmy.kde.social
168

17 replies

feddit.nl

I must ask, isn't that explicitly mentioned on the top side of the "get new..." menu?

15
lemmy.world

Some people don't read those popups.

Its entirely their fault, but it happens, and we should account for that by doing things like making these posts where people come specifically to read.

10
deadcreamreply
sopuli.xyz

What exactly do you expect users to do when they see "WARNING: what you are doing is unsafe" message? Cause the only outcome I can think of is that they won't install themes at all.

2

As someone who works in infosec, that'd honestly be an ideal outcome. Because users don't check their sources.

What would be better is if countermeasures such as not allowing that kind of code to be run by the theming engine and also code scanning on the repository with automatic takedowns on detection were put in place.

1

@deadcream @semperverus
I've used KDE for more than 10 years. I always take one of the basic themes, [varies by distro] & customize that to my liking. I've never bothered to click "get global themes". I'm willing to spend some time to have a custom theme

1

Are we all forgetting rm -rf has the --no-preserve-root safeguard? The accidental engine DataSource culprit seems unlikely. You can experiment yourself with in VM. It's only a couple lines of QML code. Nothing will happen without explicitly turning off safety.

The pling account that posted the theme was registered on February 25 2024. And suddently it has 3800 downloads without anyone else saying anything?

Things aren't adding up. I think this had to be intentional malicious crafted code.

10
iusearchlinux.fyi

Are we all forgetting rm -rf has the --no-preserve-root safeguard?

How will it help saving the important data that's in /home?

14

Unless you have your root dir mounted in your home directory! Thanks btrfs. It might be protect by permissions but I wiped a whole disk without --no_preserve_root. It hurts being too clever sometimes.

1
futurology.today

I thought wayland was supposed to improve security. Were the past 18 years a lie?

-29

I don't think that this is related to Wayland.

32
gompreply
lemmy.ml

The wayland project was originally started by George Soros... what did you expect?

-25
Lojcsreply
lemm.ee

I think this is a joke?

4

I lean center-right myself (and yet somehow continue to use Lemmy) and still marvel at the complete lunacy of conspiracy theories about him that right-wingers can dream up.

3

You reached the end

WARNING: Global themes and widgets created by 3rd party developers for Plasma can and will run arbitrary code. You are encouraged to exercise extreme caution when using these products. | Spyke