5 ms·
Vulnerability Update: libarchive
- Titanous 10y agoIf you're interested in securing software update systems, check out The Update Framework. TUF is the only system I'm aware of that has a comprehensive threat model for the problem of securely distributing software updates. https://theupdateframework.github.io https://theupdateframework.github.io
- chriscappuccio 10y agoAnd it has a BSD license, too. Unfortunately it's written in Python. I don't see Python becoming a requirement to update FreeBSD.
- akerl_ 10y agoSkimmed the spec, it sounds interesting, but I'm seemingly unable to find an architecture diagram / any kind of visualization to let me wrap my head around the actual framework. I'm not sure how connected to the project you are, but if you're aware of where I might find that, I'd be very thankful for a helping hand.
- binarycrusader 10y agoIt's not the only system, unless you assume all of the same requirements and constraints that TUF proposes as necessary. There are other systems that do many of the same things that TUF proposes. TUF also attempts to address a set of problems that some systems don't need to solve because it isn't a need they have. With that said, I would agree that TUF provides a great model.
- deleted 10y ago[deleted]
- 2trill2spill 10y ago> Around three months ago, a post was published (mirror) on GitHub's Gist service. In the report, multiple vulnerabilities against portsnap, freebsd-update, bspatch, and libarchive were detailed. To this date, FreeBSD has been silent on official mailing lists. Why didn't the poster file the bugs in the FreeBSD bug tracker and/or contact the FreeBSD security team? Even posting to the mailing list would have been better than posting on some random github page. I don't think you can fault the FreeBSD people for not seeing some random post online.
- SFJulie 10y agoHave you tried using some of the bug trackers in FOSS? Debian, python, mozilla, freeBSD are both quite a pain to use and most of all, you lose track of thee global picture. Especially when core devs have a tendency to either let the bugs opened or close them for no reasons. The unsane default of freeBSD are quite known. Having a list of them give the picture. I actually run FreeBSD to escape systemd insanity. BSD communities are far smaller than linux one, it is also a little bit «secretive» (compared to all the docs and books) on how to build drivers. Since the linux ecosystem is having all the «heavy weight» desktop applications and that freeBSD has invested quite a lot in linux compatibility I fear they lack resources to do everything. But, remember that ubuntu is providing LTS distributions with an amazing number of very used non patched packages. The state of security in linux/windows/mac OSX/BSD is a direct consequence of the multiplication of bloatware package that are poorly maintained and sometimes coded. There will be a time for cleaning.
- ashitlerferad 10y agoSubmitting a Debian bug needs a single email with one required header line, hardly a pain to use.
- jlgaddis 10y agoFreeBSD uses Bugzilla, which is a bit more work than that, but certainly nothing beyond the grasp of anyone on HN.
- rodgerd 10y ago> The libarchive vulnerabilities could allow a malicious third-party to distribute update archives that could place arbitrary files on the filesystem. Why do people keep doing this crap every time they re-invent the packaging wheel? And it's particularly awful from something purporting to be more secure than vanilla FreeBSD (which generally purports to be "better engineered" than Linux, where sane behaviour for distributing binaries is a long-solved problem).
- Jasper_ 10y ago> (which generally purports to be "better engineered" than Linux, where sane behaviour for distributing binaries is a long-solved problem). Assuming your "sane behavior" is referencing .deb and .rpm files, both of those let you run arbitrary, attacker-provided shell scripts as root whenever you install, upgrade, or even uninstall a package.
- rodgerd 10y agoBut have mechanisms to assure they aren't tampered with in-flight.
- deleted 10y ago[deleted]