I hear that all the time.operadude wrote: Thu Mar 28, 2024 4:08 am@uncle markuncle mark wrote: Wed Mar 27, 2024 8:02 pm
Yet another example of why I appreciate having become old, dull, and boring. Defaults are almost always just fine with me.
"Themes? We don't need no steenking themes."![]()
You are pure "TREASURE"![]()
KDE theme wipes user's files using 'rm -rf'
- uncle mark
- Posts: 870
- Joined: Sat Nov 11, 2006 9:42 pm
Re: KDE theme wipes user's files using 'rm -rf'
Custom build Asus/AMD/nVidia circa 2011 -- MX 19.2 KDE
Acer Aspire 5250 -- MX 21 KDE
Toshiba Satellite C55 -- MX 18.3 Xfce
Assorted Junk -- assorted Linuxes
Acer Aspire 5250 -- MX 21 KDE
Toshiba Satellite C55 -- MX 18.3 Xfce
Assorted Junk -- assorted Linuxes
Re: KDE theme wipes user's files using 'rm -rf'
Why the bloody hell are themes (of all things) allowed to execute, or be composed of, arbitrary shell scripts in the first place?! Many scoffed at Microsoft for ActiveX and the Active Desktop (and rightfully so), and now we have the same mistakes being made here. At least Microsoft had some sense not to make Windows XP themes out of executables and shell scripts.
It is hard to pull the old "oh they're just human, bugs happen" when it is the result of a fundamental architectural and design problem. As the old saying goes, those who fail to learn from history are doomed to repeat it.
It is hard to pull the old "oh they're just human, bugs happen" when it is the result of a fundamental architectural and design problem. As the old saying goes, those who fail to learn from history are doomed to repeat it.
KDE is a very large organisation which receives their fair share of funding and donations. I believe they are (or at least are considering) hiring people on a professional level. It's a shame its such a minefield in terms of customisation. You get all these wonderful options, but as soon as you activate them, kaboom bug explosion terror. If your software is like this, you really need to review your methods and stop cramming in features until it is sure that they won't break things. As much as I love KDE and use it on a regular basis, I hate that they are unwilling to accept this simple fact.AVLinux wrote: Wed Mar 27, 2024 6:56 pm It's easy to say that KDE shouldn't have let this happen but like much of Linuxdom it's probably volunteer managed or store submission devs being run on a shoestring budget... on top of that why would they be expecting to find such a heinous exploit in a theme which are almost always provided by good-hearted Users with the best of intentions in their spare time. It shouldn't have happened but KDE isn't the bad guy here the author of the exploit is... It seems like the store got on top of it very quickly, sadly, people suck...![]()
Re: KDE theme wipes user's files using 'rm -rf'
Here is Brodie's thoughts on it. https://www.youtube.com/watch?v=TvXF2jEUbO4
I am command line illiterate.
I copy & paste to the terminal. Liars, Wiseguys, Trolls, and those without manners will be added to my ignore list. 


Re: KDE theme wipes user's files using 'rm -rf'
Not sure whether the actual themes for applications or plasma desktop can contain scripts, but I think the malicious software in question was the GLOBAL "theme", which is actually more like a series of instructions to enable you to set in one click the following:AK-47 wrote: Fri Mar 29, 2024 2:53 am Why the bloody hell are themes (of all things) allowed to execute, or be composed of, arbitrary shell scripts in the first place?! Many scoffed at Microsoft for ActiveX and the Active Desktop (and rightfully so), and now we have the same mistakes being made here. At least Microsoft had some sense not to make Windows XP themes out of executables and shell scripts.
....
1. application theme
2. theme for plasma desktop
3. colour scheme
4. icon theme
5. window decorations
6. possibly some plasmoids/widgets (not sure).
Desktop: Intel i5-4460, 16GB RAM, Intel integrated graphics
Clevo N130WU-based Ultrabook: Intel i7-8550U (Kaby Lake R), 16GB RAM, Intel integrated graphics (UEFI)
ASUS X42D laptop: AMD Phenom II, 6GB RAM, Mobility Radeon HD 5400
Clevo N130WU-based Ultrabook: Intel i7-8550U (Kaby Lake R), 16GB RAM, Intel integrated graphics (UEFI)
ASUS X42D laptop: AMD Phenom II, 6GB RAM, Mobility Radeon HD 5400
Re: KDE theme wipes user's files using 'rm -rf'
It could be an intergalactic theme for all I care about. Items 1 to 5, definitely no business involving executable or shell code, even in installation or removal (these shouldn't be like deb packages).asqwerth wrote: Fri Mar 29, 2024 5:40 amNot sure whether the actual themes for applications or plasma desktop can contain scripts, but I think the malicious software in question was the GLOBAL "theme", which is actually more like a series of instructions to enable you to set in one click the following:
1. application theme
2. theme for plasma desktop
3. colour scheme
4. icon theme
5. window decorations
6. possibly some plasmoids/widgets (not sure).
I would expect this in plasmoids, but I don't think those are controlled by the global theme, from what I see in the KDE docs.
Re: KDE theme wipes user's files using 'rm -rf'
The really troubling bit is that KDE has not put a temporary halt on user submissions until their vetting process is in place.
HP 15; ryzen 3 5300U APU; 500 Gb SSD; 8GB ram
HP 17; ryzen 3 3200; 500 GB SSD; 12 GB ram
Idea Center 3; 12 gen i5; 256 GB ssd;
In Linux, newer isn't always better. The best solution is the one that works.
HP 17; ryzen 3 3200; 500 GB SSD; 12 GB ram
Idea Center 3; 12 gen i5; 256 GB ssd;
In Linux, newer isn't always better. The best solution is the one that works.