Heads up: paranoid autists chimp out over nothingburger, treat everyday software behavior as a massive security breach.
Literally all they did was add a Microsoft code repo to the list of repos that
apt install
uses to look for packages and add the GPG key required to verify the authenticity of packages received from said repo. They did this so that people could use
apt install
to install VS Code IDE. It's entirely unsurprising that they'd add that repo since the Raspberry Pi Foundation officially endorses the software.
They didn't compromise anyone's security or invade anyone's privacy. The update was part of a
publicly-announced change to the
raspberry-pi-sysmods
package — the code that adds the repo and GPG key is in the
postinstall script. The only way this repo was added to anyone's Raspberry Pi without their knowledge is if they blindly updated that package without reading the changelog, i.e. were so careless that they've lost all right to bitch about privacy and security.
Shit, it's not even a big deal to have this repo on your list unless you're a tinfoil pantshitter who cares about Microsoft knowing that there's a Raspberry Pi at whatever IP address you're running it on. If you use
any Microsoft software you're already giving them similar information, and quite possibly a lot more unless you've gone out of your way to lock shit down. Anybody who's concerned enough about Microsoft to be upset by this change should already be blocking Microsoft's shit at a firewall level anyway.
The Raspberry Pi is a mass market "learn to code" box. Microsoft Visual Studio is an incredibly popular IDE, especially in educational settings. Raspbian updated their software to make it easier for people to install the "learn to code" IDE on their "learn to code" box. As a result, a bunch of people who apparently didn't learn to code very well decided to collectively shit their pants over nothing. That's all that happened here.