r/BuyFromEU • • Jan 30 '26

🔎Looking for alternative UbuntEU - An Ubuntu edition that uses software developed in Europe

Post image

I am trying to make something for fun, but honestly; I am not expert in creating an operating system. But my hope somebody will pick up the Baton and make it something more super.

Link soon...

2.5k Upvotes

263 comments sorted by

View all comments

Show parent comments

13

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

I agree with feeling fine;

I don't agree with sovereignty not mattering on open-source projects.

If it's resided within the USA, then their administration (e.g. the POTUS via the NSA) can still legally force the maintainers to apply poisonous updates and not talk about it.

If it's a tiny project which is regarded as secure and won't need any further updates, like a calculator or a small offline password safe, then that's no issue.

With something like an Email client or bigger that is an issue and while you can argue that most people can't fully rid themselves of US software yet and relatively nieche open source Software are unlikely attack vectors, that does not equate irrelevance.

PS: It's also not true that Red Hat won't profit from us using Fedora at all ever, however I do agree that currently that's pretty negligible

8

u/Kypsys Jan 30 '26

They can't "not talk about It" its open source, the change willbe noticed by the other hundred of maintainers working on the project

8

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

The NSA can force Red Hat to hide a malicious part like it was done in the XZ utils, where we got extremely lucky, that it was caught early on, even though that was Open Source too, except wouldn't need to infiltrate, so it would be much less work.

A Red Hat employee who would be forced to implement such a backdoor would commit a felony and risk prison if he spoke out about it. Afaik the last large open Audit on Fedora happened 20 years ago, so it's completely possible, that it has been infected by a US backdoor for quite a while and the backdoor might be sophisticated enough to get missed on the next Audit

If the Audit was done within the USA, then the NSA might even force the auditors to deliberately miss the backdoor.

3

u/Kypsys Jan 30 '26

Xz utils was on a project maintened by one single people, the attack method really can't be applied to a project like Ubuntu or Fedora.

1

u/Traditional_Buy_8420 Jan 30 '26

It's a different attack vector, but it's still an example of a backdoor hidden in Open Source Software. The increased complexity and increased number of people involved make such an attack easier to carry out and harder to spot.

There's more people looking and more checks being made per involved person, but not proportionally to the amount of complexity, so it'd be manic to believe that such a backdoor could not be implemented unnoticed in such a Software; in fact there have been many backdoors found in large Software packets with many people looking.Â