Arrggh! beware the upgrade...

Dec 19, 2023 Last reply: 2 years ago 136 Replies

Hmm - sooner or later they're going to realise that ...

a) Data centres are expensive and unpopular b) Users have oodles of unused compute and store resources c) Many of them have high bandwidth internet connections d) Distributed architectures can be very robust

... and start parking VMs in customers computers and lacing them together in VPNs to provide the services they're selling. Your downloaded application will in fact be a remotely administered hypervisor.

How do they propose to install that on my machine without anyone noticing?

Malware authors have been hiding their applications for years...

I don’t think there’d be much demand for compute running on randos’ computers from legitimate buyers though. Cloud works for people who trust Amazon (et al) to provide a sufficient degree of resilience, security etc for their use cases. You don’t get that from random third-party computers.

No doubt there are use cases where the poor reliability of domestic compute wouldn’t be an issue, and there are several interesting responses to the obvious security issues (e.g. secure execution environments, cryptographic trickery) but it could be a rather small niche.

Also the above situation might or might not be an issue. I certainly have had that work on my boxen at times. But it isn't very common, and far less common that it was.

Although presumably you can get into the same situation with external / third party / private packages. And with any good package management system

- I include dpkg (even though that is typically binary based) and portage and FreeBSD's ports - not very common at all.

Yes but hopefully one with rules that you choose to join rather than one that just takes root in your systems.

You install the cloud application suite, it consists of the hypervisor which phones home, adds your resources to the pile and offers you all the cloud applications you just signed up for.

There are practically none of those - there are a few special purpose repos and associated build farms but not very many. It's so much easier to create ports and get them added to the ports tree than it is to maintain a separate package set. Port maintenance is generally pretty light work - and the package build and distribution comes for free from the project infrastructure.

The downside is a long cycle time for package updates that gets longer as more ports are added and shorter when more hardware is thrown at the task.

There are people who build all their own packages in house (they get much shorter cycle times by only building the ones they use and they get to set the build optiopns), using the same system as the official package builds - they tend not to install from the official repo and of course they get consistent sets.

You can get in a mess but it takes a bit of determination.

The trouble I've seen with .deb packages either Ubuntu or Debian sourced is that most of the old versions are available and it is common to add external repos so the set of packages available to apt is not a consistent one especially if you insist on installing a particular version for one or more packages and/or don't update them all every time.

With FreeBSD packages extra repos and pinned versions are rarities. This tends to mean that if it's not already in the ports and producing a package (some ports don't for licence reasons - some are broken) then you are SOL unless you can create a port yourself (which varies from dead easy to a nightmare requiring deep skills in several languages and an understanding of the application code).

As others have said - no it is not. Your statement is just false.

Like the SETI@home. I think they did it as a screen-saver?

In the past, some companies used staff's desktop PCs to run compute intensive overnight batches. It is quite tricky to set up and manage. I'd be surprised if it was economic for most companies, as opposed to using Google, Amazon, or Microsoft cloud servers.

From an IT management viewpoint, it is easier to manage centralised servers and smart terminals. I assumed that was the way things had gone over the last decade? Cheap, low cost PCs, with serious computations done on a server or the cloud..

So, just rumors and on top of that your speculation? I will not bet any money an that happening soon...

No I don't. I've not completed iCloud setup on my iPhone or any of my Macs. End of.

Well sort of - except that even the cheap low cost PCs tend to have quite a lot of CPU, RAM and disc and with all the real work happening in the cloud it's idle and of course quite a lot get fancy big fast PCs which get even less use because they're too far up the greasy pole to actually work.

That's you and me safe then.

formatting link
instance...

Oh they can be much more open about it - after all they're not rooting your machine, they're just using it to provide the service you've payed for.

<IANAL - I've just heard too many of them scheme>

They probably already have

I actually was trying to watch free sport on my Linux PC and I noticed that my OUTGOING data rate was maxed out...some kind of video proxying going on via one assumes javascript

That's just God's punishment for running Windows.

Linux/Unix are NOT "perfect". I don't think anything can be.

However, properly implemented, they can significantly REDUCE the number and scope of problems. Winders just CAN'T. It's a total disorganized incomprehensible cluster-f*ck.

The infamous "buffer overflow" continues to be a major issue. Winders is just FULL of bad code that allows overflows to do their evil. And no, it won't/can't "just be fixed-up" because nobody even knows how it all WORKS anymore. Kludges on top of kludges on top of kludges going back into the 80s.

"Rust" is not a panacea. IMHO it's just another language created "because we could". 'C' is still the gold standard. I proto in a lot of languages, but the final product always winds up being in 'C' or Pascal. If you're REALLY paranoid then a native ADA compiler, even though it's a just HATEFUL language to use (no wonder Defense projects go 10X over budget and are 10X later than promised ......)

Kernels DO need to be tighter. So far, Linus has been pretty sharp this way - enough to put-off a lot of would-be "improvers" who would crash lots of other stuff to make a few gee-whiz things "easier".

But Linus isn't young anymore. What then ?

Unix/BSD are more conservative. This has plusses, and minuses. ,

As is, never expect "perfection". Every system, no matter how clever, will always have flaws - and the Evil People will eventually FIND them. It's a running battle. However solid underlying design will REDUCE the number of exploitable flaws.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required