5 ms·
The OS X binary isn't signed, and the download URL is HTTP. Is there a version available on a more secure distribution channel anywhere?
by mjs 10y ago
The OS X binary isn't signed, and the download URL is HTTP. Is there a version available on a more secure distribution channel anywhere?
- marcusarmstrong 10y agoIf you git clone and compile from source [0], that should do the trick (In that it gets you an HTTPS download), I think. [0] https://github.com/browserhtml/browserhtml#building-and-running https://github.com/browserhtml/browserhtml#building-and-runn...
- Manishearth 10y agoWe're switching the download link over to HTTPS. Is there a reason the OSX binary needs to be signed? We don't do anything special. Edit: HTTPS up: https://servo-builds.s3.amazonaws.com/index.html https://servo-builds.s3.amazonaws.com/index.html (This comment written in Servo :P )
- voltagex_ 10y agoAFAIK recent OS X versions won't allow you to launch unsigned binaries by default. Windows 10 has a similar feature.
- paws 10y agoWhile Gatekeeper is on by default and the ability to adjust it has been restricted to command-line only in Sierra, it is still possible to disable it.
- voltagex_ 10y agoMozilla are lucky enough to be able to afford a code-signing certificate and I'm pretty sure their build process can be adjusted to sign binaries by default. It's unfortunate that a LetsEncrypt style project can't be done for code signing, due to malware/admin overhead.
- daenney 10y agoThere's no need to do that. Just right-click on Servo.app and select "Open". A dialogue will pop up asking you if you're absolutely certain and off you go.
- threeseed 10y agoThe last few releases of OSX don't allow you to launch unsigned binaries without specifically disabling the check. In the latest Sierra beta I've heard you can't disable the check without an involved workaround. It's just OSX users being lazy ;)
- Manishearth 10y agoHuh. I've only recently started using OSX, and I've had codesign issues when using self-compiled debuggers, but not when using things like servo. Can it be signed by any old cert or does it need to be part of the trust chain?
- LnxPrgr3 10y agoDebuggers are special--the OS won't let unsigned binaries control other processes, no matter how they came to exist on your system. Outside of that, Gatekeeper applies to executables fetched from the Web, can be disabled (harder on Sierra), and is easy enough to bypass--and you only have to do it once per executable. If signed, the certificate does need to be trusted to count--otherwise, it'd just be a fancy checksum.
- Manishearth 10y agoAlright. This sounds like something we should be eventually doing. Not sure if we should prioritize it right now. GPG-signing the binaries for extra verifiability is another thing we could do in the meantime, though it doesn't fix the OSX issue.
- Argorak 10y agoYou need an Apple Developer Cert. Here's the relevant tracking issue for the same problem in Rust. https://github.com/rust-lang/rust/issues/27694 https://github.com/rust-lang/rust/issues/27694
- Longhanks 10y agoSince when does unwillingness to disable security features equal laziness?
- k_bx 10y agoIf you install Servo as of now and try to launch it you'll get a pop-up saying it's not signed (and it won't launch). So, to launch, you need to go to Applications, right-click on servo and choose "launch". Then it'll let you say "yes, run this unsafe executable". Might reduce number of users who can figure this out.
- paws 10y agoI see where you're coming from. Gatekeeper is nice in some important ways but seeing as it isn't free, I'd also be quite happy with just a SHA1 or similar signature to verify a binary with.
- cbrewster 10y agoThe issue with the codesigning is mentioned on download.servo.org, hopefully in the future, we can set up some infrastructure to codesign the app. :)