Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Caution: don't add Qmmp player binaries in the future if somebody requests for user safety #12884

Open
Tomurisk opened this issue Mar 1, 2024 · 0 comments

Comments

@Tomurisk
Copy link

Tomurisk commented Mar 1, 2024

I was looking for a simple audio player, that would have Winamp functionality and old-school design, would be low on system resources and had compact design. Being unaware that the original Winamp is supported, I stumbled upon this gem (in a negative way from now on): Qmmp. I thought of giving it a try, then I recognized the Russian state-backed Astra Linux running Qmmp in screenshots, then for some reason clicked on a yellow leaf under the "hits" number. Oh boy, that's the parent site, apparently. The first thing I'm met with is a beautiful nationalistic pro-Russian post by one of the developers, claiming that "for a number of reasons, the transition to domestic software products is becoming not just an act of patriotism, but also a serious necessity" with a Google Sheets spreadsheet linked, that whines about software developers protesting (I agree that some of the means aren't exactly ethical), companies cutting business with Russia, blocking access to services, and "Ukrainian propaganda", such as anti-war statements, Free Russia blue-white-blue flags for the Russian language. Readers in the spreadsheet are encouraged not to use Ukrainian software and compiled executables/dynamic libraries because "nobody knows what they contain".

That being said, when such content gets published by a developer, this particular piece of Russian software should be explicitly avoided. The Windows binaries should be treated as compromised, despite the openness of source. And given the unhinged blog post, along with deletion of my sarcastic response to the statement, such software poses a great risk of potential sabotage.
The parent site in question
RU -> EN spreadsheet

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant