logoalt Hacker News

drdexebtjltoday at 4:49 AM2 repliesview on HN

This sounds like a prime new vector for malware, ironically.


Replies

scott_wtoday at 5:16 AM

My understanding is probably not: the hooks are configured locally, not by other packages automatically, so you’d install and setup the pre-install hooks yourself to check the packages before install/update.

Can it be exploited? Yes, anything can. But that’s not a reason to not do this if the overall result is better.

self_awarenesstoday at 5:51 AM

And how a malware can use this if it's configured globally in a root:root owned config file?

show 1 reply