8 ms·
Open source software can be verified.
by hackuser 10y ago
Open source software can be verified.
- enduser 10y agoSource code can be verified. Binaries distributed via app stores may or may not have behavior different from the published code.
- jMyles 10y agoCertainly it's possible to remedy this situation simply by having the app author sign a checksum of binaries in the app store. Why this is not currently an option (to my knowledge) is a mystery to me.
- obscene 10y agoThat doesn't protect you against a malicious developer.
- jMyles 10y agoYou mean someone publishing source code and then falsely verifying the binary checksum? I mean, at the end of the day, it's very easy to verify - if the binary doesn't match what whomever gets when they compile, there better be a reason for it. Regardless, I don't think this is the biggest problem facing open source.
- Groxx 10y ago>if the binary doesn't match what whomever gets when they compile, there better be a reason for it. True, but deterministic compiles are stupendously difficult in most cases. Which is improving slowly, but still isn't usually an option.
- BuuQu9hu 10y agoDebian is up to 92% deterministic builds, so not that hard: https://tests.reproducible-builds.org/debian/reproducible.html https://tests.reproducible-builds.org/debian/reproducible.ht...
- Groxx 10y agoOoh, that is a heck of a lot better than the last time I looked at it. And a very neat link - thanks!
- Groxx 10y agoIt kinda is - you could add it to the description. App stores seem to be getting progressively more hostile to this kind of thing though - you can't just download an APK / iOS app, you have to do it through a device. This lets the stores do "app slimming" (and per-country / per-carrier customized apks) to remove resources you don't need (like binaries that don't match your architecture), which would change the checksum. Which is useful, but inconvenient for this goal. Something like fdroid may be supportive of this, which would be cool. But I wouldn't expect the mainstream ones (or Apple) to ever embrace it - it'd be a bad user experience / wasted UI space in the vast majority of cases.
- mos_basik 10y agoIt's been a while (a couple of years) since I last tried this, but I remember it being reasonably straightforward to get APKs of apps that were on the Google marketplace. Not through official user interfaces, of course. I can't remember if I ended up using some Chrome extension or a third-party app that needed root. Not a particularly useful comment sorry, just "it was possible two years ago if you jumped through some hoops."
- Groxx 10y agoYou can probably still get the one that'll install on your device(s), but if there's customization for e.g. carrier X in country Y (or app slimming) you're unlikely to know or be able to find it from the infinite "download APKs free now!" sites. And the last time I looked, all the apk-downloaders required your device ID, because Google's API does (for customization reasons) - it's much more of a "you can do this if you emulate a device" than "you can download it". I'm also not sure if the ID works unless you have gplay installed, which you may not have if you're being careful/paranoid enough about security to manually validate apps.
- maxerickson 10y agoWhat would a checksum add over the app binary being signed by the author (which is currently the case for both stores)?
- jMyles 10y agoUmmm good question. I feel silly for making this point now.
- halomru 10y agoAny open source project can allow you to verify binaries by making builds reproducible. The fact that most apps don't do this is indeed a security problem, but one that's far from unfixable.
- thesimon 10y ago> Source code can be verified But how often is that really done? And to be honest, it can be quite hard to spot critical bugs or backdoors, just look at http://www.underhanded-c.org/ http://www.underhanded-c.org/
- DINKDINK 10y agohttps://gitian.org/ https://gitian.org/ The bitcoin development community solved the problem of mapping source code to a binary build. Check sums or signatures of binaries is not sufficient. Open source is meaningless if you cannot verify the source maps to the build and you're running critical software with irreversible consequences. E.g. a bitcoin transaction or a dissident being imprisoned from state surveillance eaves dropping on communications.
- andrepd 10y agoYou can build and check against the binaries. What's your point?
- Ao7bei3s 10y agoReproducible builds will fix that, soon.
- UncleMeat 10y agoTo do this you must not only verify the open source code, but that the binary was built from this code, and that your operating system and every layer below it is also trustworthy. I stand by my claim that using software written by a malicious developer is game over in the vast majority of contexts.
- gshulegaard 10y ago> verify the open source code The argument here is that open source code can be verified where closed source is explicitly non-verifiable by nature. > but that the binary was built from this code Doesn't code signing address this? If not could you explain (for my own learning)? https://en.wikipedia.org/wiki/Code_signing https://en.wikipedia.org/wiki/Code_signing > that your operating system and every layer below it is also trustworthy. Yep, this is the last major piece for true security in my mind. Although there is some movement in the open hardware space as well as USB mounted OSs (http://gizmodo.com/try-the-super-secure-usb-drive-os-that-edward-snowden-i-1563320487 http://gizmodo.com/try-the-super-secure-usb-drive-os-that-ed...). > I stand by my claim that using software written by a malicious developer is game over in the vast majority of contexts. Sure...perfectly accurate...but in the context you are implying that WhatsApp is malicious. To which I think "hackuser" was interpreting as "closed source is malicious" and therefore offering open source (and by implication Signal) as an alternative. Might just be a miscommunication moment :-)
- kasey_junk 10y ago> The argument here is that open source code can be verified where closed source is explicitly non-verifiable by nature. This is not a belief that people who actually do software security audits hold. Verifying binary only software is table stakes to a security audit of a third party application as you cannot trust the source provided. Having source is a bonus for security audits not a requirement.