Ubuntu decided to remove uptime from motd-news' data leak (exfiltration)
via User-Agent: and move /etc/default/motd-news conffile to the motd-
news-config package and switch from curl to wget.

Remove uptime from the motd-news user agent 
https://bugs.launchpad.net/ubuntu/+source/base-files/+bug/1886572

motd-news: use wget instead of curl
https://bugs.launchpad.net/ubuntu/+source/base-files/+bug/1888572
-- I hope they will stop launched it as root as well
see https://github.com/curl/curl/issues/5557

Split motd-news config into a new package
https://bugs.launchpad.net/ubuntu/+source/base-files/+bug/1888575

To Be
Continued --->

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to base-files in Ubuntu.
https://bugs.launchpad.net/bugs/1867424

Title:
  motd-news transmitting private hardware data without consent or
  knowledge in background

Status in base-files package in Ubuntu:
  Won't Fix

Bug description:
  In package base-files there is a script /etc/update-motd.d/50-motd-
  news that harvests private hardware data from the machine and
  transmits it in the background every day.  There is no notice, no
  consent, no nothing.  This should be by default disabled until there
  is informed consent.

  This solution is simple:

  1. Change ENABLED=1 to ENABLED=0 in the file /etc/default/motd-news and 
  2. Place a comment in the file disclosing the fact that the 50-motd-news 
script will harvest private hardware data and upload it to motd.ubuntu.com 
daily if the end-user enables it.

  Creating databases that maps ip address to specify hardware is a
  threat to both privacy and security.  If an adversary knows the
  specific hardware and the ip address for that hardware their ability
  to successfully attack it is greatly increased.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/base-files/+bug/1867424/+subscriptions

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to