Security leak: Public disclosure of user data without their consent by installing software via pkg
shawn.webb at hardenedbsd.org
Tue Apr 6 14:42:28 UTC 2021
On Tue, Apr 06, 2021 at 04:39:40PM +0200, Miroslav Lachman wrote:
> On 06/04/2021 16:27, Shawn Webb wrote:
> > 1. BSDStats isn't run/maintained by the FreeBSD project. File the
> > report with the BSDStats project, not FreeBSD.
> > 2. You install a package that is made to submit statistical data.
> > 3. You're upset that it submits statistical data?
> The problem here is that it collects and sends data right at the install
> time. It is really unexpected to run installed package without user consent.
> If you install Apache, MySQL or any other package the command / daemon is no
> run by "pkg install" command.
> This must be avoided.
It's probably easier to submit a patch than it is to write a
lolwut-type email. All you gotta do is rm the post-install script.
Also `pkg install` has the -I option. But whatever, let the lolwut
Cofounder / Security Engineer
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the freebsd-security