All messages received over a year (Ubuntu 18.04):

* Congrats to the Kubernetes community on 1.16 beta 1! Now available
* Kata Containers are now fully integrated in Charmed Kubernetes 1.16!
* Keen to learn Istio? It's included in the single-package MicroK8s.
* Kubernetes 1.18 GA is now available! See https://microk8s.io for docs or
* Latest Kubernetes 1.18 beta is now available for your laptop, NUC, cloud
* MicroK8s 1.15 is out! It has already been installed on more
* MicroK8s 1.15 is out! Thanks to all 40 contributors, you get the latest
* MicroK8s passes 9 million downloads. Thank you to all our contributors!
* Multipass 1.0 is out! Get Ubuntu VMs on demand on your Linux, Windows or
* Multipass 1.1 adds proxy support for developers behind enterprise
* Overheard at KubeCon: "microk8s.status just blew my mind".
* 'snap info' now shows the freshness of each channel.
* Ubuntu 20.04 LTS is out, raising the bar on performance, security,
* Ubuntu's Kubernetes 1.14 distributions can bypass Docker and use containerd

None of them are about security and none of them are customized
using uptime, ubuntu version, kernel version, curl version, ip, ...

Why do pack all this into User-Agent which can be linked to public IP
every 12 hours?


** Attachment added: "motd-news.txt"
   
https://bugs.launchpad.net/ubuntu/+source/base-files/+bug/1867424/+attachment/5381565/+files/motd-news.txt

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to base-files in Ubuntu.
https://bugs.launchpad.net/bugs/1867424

Title:
  motd-news transmitting private hardware data without consent or
  knowledge in background

Status in base-files package in Ubuntu:
  Confirmed

Bug description:
  In package base-files there is a script /etc/update-motd.d/50-motd-
  news that harvests private hardware data from the machine and
  transmits it in the background every day.  There is no notice, no
  consent, no nothing.  This should be by default disabled until there
  is informed consent.

  This solution is simple:

  1. Change ENABLED=1 to ENABLED=0 in the file /etc/default/motd-news and 
  2. Place a comment in the file disclosing the fact that the 50-motd-news 
script will harvest private hardware data and upload it to motd.ubuntu.com 
daily if the end-user enables it.

  Creating databases that maps ip address to specify hardware is a
  threat to both privacy and security.  If an adversary knows the
  specific hardware and the ip address for that hardware their ability
  to successfully attack it is greatly increased.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/base-files/+bug/1867424/+subscriptions

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to