Re: Security leak: Public disclosure of user data without their consent by installing software via pkg

Gordon Tetlow via freebsd-security <[email protected]>
Newsgroups gmane.os.freebsd.security.general
Message-ID <[email protected]>
On Apr 6, 2021, at 7:42 AM, Shawn Webb <[email protected]> wrote:
> 
> On Tue, Apr 06, 2021 at 04:39:40PM +0200, Miroslav Lachman wrote:
>> On 06/04/2021 16:27, Shawn Webb wrote:
>> 
>>> 1. BSDStats isn't run/maintained by the FreeBSD project. File the
>>>    report with the BSDStats project, not FreeBSD.
>>> 2. You install a package that is made to submit statistical data.
>>> 3. You're upset that it submits statistical data?
>> 
>> The problem here is that it collects and sends data right at the install
>> time. It is really unexpected to run installed package without user consent.
>> If you install Apache, MySQL or any other package the command / daemon is no
>> run by "pkg install" command.
>> This must be avoided.
> 
> It's probably easier to submit a patch than it is to write a
> lolwut-type email. All you gotta do is rm the post-install script.
> Also `pkg install` has the -I option. But whatever, let the lolwut
> mentality prevail!

I had a conversation on the side with the requestor. In short, there is already a patch to address this issue in https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=251152 <https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=251152>. Not sure why it hasn't been committed yet, but hopefully it gets picked up shortly.

Gordon
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEuyjUCzYO7pNq7RVv5fe8y6O93fgFAmBsdpMACgkQ5fe8y6O9
3fh8Bwf6AzhluVmpBSM0xzMj92SJFPjKoJGUbQZr26W+yQiosUg4798OexCZ6wse
iFrEykkeK6QbkfHqrRojxzmQGQR0au903RA/U5UpYlatMqWYpoeijHc419/dnmXw
33IXcgJb4wBrSonQ7lhGlidD35wDzqHjESqfsgIkwTjUxGItbeUy9Yzh9F9W8OoR
DLWWdlJdIEGBChjr4P35+RgLSU8ylJrQwjdRkldfHHm2mn8P1fyqnmmRfX7xsWyD
fusBofOIDERAeqbuYiu1yCB0BjmG2lUUWIZ517Ou2Gr7HRD7DbPa/W2vRanc2N5I
J2xg3Wy39Xdg7lxruPjhl8R9XqIP9A==
=0UGI
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.