• 0 Posts
  • 31 Comments
Joined 2 months ago
cake
Cake day: February 5th, 2025

help-circle

  • Xanza@lemm.eetolinuxmemes@lemmy.worldVentoy my beloved.
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    5
    ·
    18 hours ago

    The advantage of Ventoy is its ability to work in any environment and handle 99% of ISOs. Compiling the binaries at build time requires a mature development environment to be able to build these utilities… Your exponentially increasing the size and complexity of the project to solve a relatively minor security issue.

    Ventoy is not the only way to create a bootable drive… If you don’t trust the blobs then don’t run the software.

    Forking ventoy to add the complexity of building these utilities is only going to be available for *nix base environments so Windows users are pretty much shit out of luck. Your exponentially increasing the size of the project, it’s complexity, and simultaneously significantly narrowing its usability…

    I said it before and I’ll say it again it’s such a bad fucking argument. It’s not mature software. It’s a literal confluence of hacks… And if you’re not comfortable with using it then don’t use it. It really is a huge security risk. But advocating that nobody use it is such stupid fucking thing.

    Advocate that people understand the risks of using it but to just run around and scream about how nobody should be using it for any reason whatsoever until the maintainer closes the security hole that makes it run is pretty stupid.





  • Xanza@lemm.eetolinuxmemes@lemmy.worldVentoy my beloved.
    link
    fedilink
    English
    arrow-up
    39
    arrow-down
    9
    ·
    edit-2
    23 hours ago

    No. But the argument itself is so stupid to me.

    Ventoy has never been a secure tool. People are making the argument that it should be, which is just nutty.

    If you’re one of those people that grab random fuckin’ ISO’s from all over the internet to test em out, then no. You really shouldn’t use Ventoy. If you run official ISO from recognized sources, then realistically the risk is ever present, but minimal.

    Like getting in a wreck on the way to the store to pick up milk. It’s always a possibility, but not many people would stand around and make the argument that you should stay home forever because you might get into an accident, which is basically the argument against Ventoy. It’s “we’ll, it’s a crazy useful tool, but you shouldn’t use it because something might happen.”

    It’s just such a bad argument. Fact of the matter is, is that if there were a non-hacky as shit way to do what Ventoy does, it would be available right now. But it’s not… Because it’s really not.

    The only way to avoid the issues that Ventoy employs is to not use ISOs and use something like netboot.xyz, which presents its own set of issues. How do you know you’re not being MITM from the iPXE environment? Like, sure. You can technically verify it, but how do you know for sure on the fly?

    Like, if you sit down you can pick apart any software for being an insufferable gaping asshole of security vulnerabilities.








  • It’s amazing to me that you have your head so far up your ass that you have the balls to say shit like this when Republicans are literally in the White House right now showing you exactly who they are.

    Firing tens of thousands of people. Destroying the economy in the same way that we did during the Great Depression with tariffs–which have the exact same chance of working now as they did back then. Alienating every ally we have on this planet. Breaking the law with every single official action they make and then complaining about the courts trying to stop them from doing these illegal actions as if the courts are doing something wrong. They’re literally abducting students off the fucking street.

    You can complain about Democrats until Kingdom come and you’ll most likely be right about them. But you can never again in the remaining time we have left on this planet put Democrats and Republicans side by side is if they’re the same anymore.

    You just can’t fucking do that because it’s not fucking true, and all you have to do to definitively prove that beyond any measure of any doubt is to look at what the White House is doing today…

    You don’t get to pretend like the parties are basically the same and we can just agree to disagree. You don’t get to do that anymore. Be as as critical as you want with Democrats. Go to town. But at the end of the day when given the chance Republicans went completely off the fucking rails and went 120% authoritarian.

    You can never again make the argument that the two parties are basically the same. Because we have irrefutable empirical evidence that isn’t true…


  • But have you heard, “blue no matter who.”

    Slogans and behavior like this are directly the fault of the other party. There would be no need for “blue no matter who” if we didn’t have Republicans who refused to discuss education, poverty, social security, medicaid, or any of the other very popular talking points the rest of the Government…you know… Governs on.

    You can’t have people like what’s her name Greene talking about Jewish space lasers and then refuse to speak about education reform for her state… You just can’t. We need serious people in power, and if you can’t bring any to the plate, then I’m going to choose from those who are at least willing to speak on education. And if that’s only democrats, then…blue no matter who.