The Register Home Page

back to article Canonical cracks down on crypto cons following Snap Store scam spree

After multiple waves of cryptocurrency credential-stealing apps were uploaded to the Snap store, Canonical is changing its policies. In what's expected to be a temporary measure, an announcement on the Snapcraft Discourse says that the Ubuntu vendor will switch to manual review of all new snap name registrations. The post from …

  1. Neil Barnes Silver badge

    The Reg FOSS desk takes an extremely jaundiced view of this.

    The Reg FOSS desk is not the only one. Don't touch 'em and you'll never be scammed.

  2. Groo The Wanderer Silver badge

    Pardon me while I cry crocodile tears for people still playing with bitcoins. *LOL*

    1. MDMAok

      It's all very well for you youngsters, but all the people used to buy weed from are dead of old age. So I need bitcoin....

    2. dd123

      It amazes me that people commenting on this topic focus on scammed person being bitcoin user and not on who is responsible for this problem (which is Canonical)

      > Part of the problem is that these apps look legitimate to casual inspection because the Snap Store badges them as "safe."

      Let people use whatever they like on their PCs. And let them be sure that whatever they use, it comes from legitimate source.

    3. werdsmith Silver badge

      Pardon me while I cry crocodile tears for people still playing with bitcoins. *LOL*

      Help me understand why? Bitcoin is at a record high and people who have invested in bitcoin are absolutely quids in.

      I made an absolute mint out of it, and if I had held on I could have made a triple mint.

      1. Jumbotron64

        I remember Tulips being at an all time high….

        1. werdsmith Silver badge

          Plenty of tulip millionaires in The Netherlands.

          1. Jumbotron64

            Not anymore…except for the ones fertilizing the newest batch.

  3. Kevin McMurtrie Silver badge

    Good news

    The Snap Store usually doesn't work.

  4. remainer_01
    Thumb Up

    Douze points

    Douze points for the headline, well done folks.

  5. Anonymous Coward
    Anonymous Coward

    12 years of Ubuntu ESM!? Feels like a life sentence

    In a way I really wish that they would stop extending it because every time this happens it allows my lords and masters to de-prioritise the urgent upgrades due to EoSL or the end of ESM and return to their favourite pastime of kicking the can down the road.

  6. herman Silver badge

    So Canonical has a problem with protecting criminals and scammers from each other, because it creates bad press?

  7. Anonymous Coward
    Anonymous Coward

    "Now you know why it's called snap", said the crocodile

    Wait, so any old ne'er-do-well can just upload any old malware to the snap repository? «rolls eyes»

    That's yet another point in favour of the traditional Debian (and derivatives) repo system, then, where package maintainers have to earn trust and be approved before packages can be approved, and there is (hopefully) more than one trusted person looking at changes to each package.

    That "move fast and break things" meme yet again proving that the second part needs to be highlighted much more than the first…

    1. Anonymous Coward
      Anonymous Coward

      Re: "Now you know why it's called snap", said the crocodile

      Canonical must have learned the "no QA checks" from their close association with Micro$oft. A lot of Linux Mint users must be happy that Mint blocks Snaps by default (you can enable them if you want).

  8. johnandmegh

    Any different response this time?

    Last time, there was a temporary restriction on new uploaders, then the restriction was lifted with (apparently) no further controls in place...so the cycle repeated.

    There are several steps that could be taken to improve the situation - like forcing user visibility to the app's manifest in the store, like Flathub - that wouldn't require incremental review time by the Canonical/Snapcraft team for each new app.

    My fear is that it'll simply be another "wait out the storm" situation, and that next time, the malicious apps might be in a category that's not quite so easily dismissed as crypto.

  9. dd123

    Snaps just ruins the biggest advantage of Linux OS'es...

    ... which is reliable and peer-reviewed software repos.

    This is what I loved in Ubuntu, that I could just set up server just using APT and I could be pretty sure that nothing I've installed is malware and won't do any greater damage. And the software I'm installing is indeed the software I was thinking about, not just similarly named scam. And now Canonical brings Snaps and ruin that all.

    1. Jumbotron64

      Re: Snaps just ruins the biggest advantage of Linux OS'es...

      It’s not Snaps as a containerized framework that is the problem, seeing as how it is head and shoulders ahead of Flatpak and the laughable App Image in production, manageability and security, but Canonical not yet realizing they have become the Google or Apple of Linux world in Snaps creation and in a Snap Store. They need to quickly and competently scale up their inspection, verification and certification department to the order of a Google or better yet Apple.

    2. ianbetteridge

      Re: Snaps just ruins the biggest advantage of Linux OS'es...

      And you stil can?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like