4 ms·
Source code can be verified. Binaries distributed via app stores may or may not have behavior different from the published code.
by enduser 10y ago
Source code can be verified. Binaries distributed via app stores may or may not have behavior different from the published code.
- jMyles 10y agoCertainly it's possible to remedy this situation simply by having the app author sign a checksum of binaries in the app store. Why this is not currently an option (to my knowledge) is a mystery to me.
- obscene 10y agoThat doesn't protect you against a malicious developer.
- jMyles 10y agoYou mean someone publishing source code and then falsely verifying the binary checksum? I mean, at the end of the day, it's very easy to verify - if the binary doesn't match what whomever gets when they compile, there better be a reason for it. Regardless, I don't think this is the biggest problem facing open source.
- Groxx 10y ago>if the binary doesn't match what whomever gets when they compile, there better be a reason for it. True, but deterministic compiles are stupendously difficult in most cases. Which is improving slowly, but still isn't usually an option.
- BuuQu9hu 10y agoDebian is up to 92% deterministic builds, so not that hard: https://tests.reproducible-builds.org/debian/reproducible.html https://tests.reproducible-builds.org/debian/reproducible.ht...
- Groxx 10y agoOoh, that is a heck of a lot better than the last time I looked at it. And a very neat link - thanks!
- Groxx 10y agoIt kinda is - you could add it to the description. App stores seem to be getting progressively more hostile to this kind of thing though - you can't just download an APK / iOS app, you have to do it through a device. This lets the stores do "app slimming" (and per-country / per-carrier customized apks) to remove resources you don't need (like binaries that don't match your architecture), which would change the checksum. Which is useful, but inconvenient for this goal. Something like fdroid may be supportive of this, which would be cool. But I wouldn't expect the mainstream ones (or Apple) to ever embrace it - it'd be a bad user experience / wasted UI space in the vast majority of cases.
- mos_basik 10y agoIt's been a while (a couple of years) since I last tried this, but I remember it being reasonably straightforward to get APKs of apps that were on the Google marketplace. Not through official user interfaces, of course. I can't remember if I ended up using some Chrome extension or a third-party app that needed root. Not a particularly useful comment sorry, just "it was possible two years ago if you jumped through some hoops."
- Groxx 10y agoYou can probably still get the one that'll install on your device(s), but if there's customization for e.g. carrier X in country Y (or app slimming) you're unlikely to know or be able to find it from the infinite "download APKs free now!" sites. And the last time I looked, all the apk-downloaders required your device ID, because Google's API does (for customization reasons) - it's much more of a "you can do this if you emulate a device" than "you can download it". I'm also not sure if the ID works unless you have gplay installed, which you may not have if you're being careful/paranoid enough about security to manually validate apps.
- maxerickson 10y agoWhat would a checksum add over the app binary being signed by the author (which is currently the case for both stores)?
- jMyles 10y agoUmmm good question. I feel silly for making this point now.
- halomru 10y agoAny open source project can allow you to verify binaries by making builds reproducible. The fact that most apps don't do this is indeed a security problem, but one that's far from unfixable.
- thesimon 10y ago> Source code can be verified But how often is that really done? And to be honest, it can be quite hard to spot critical bugs or backdoors, just look at http://www.underhanded-c.org/ http://www.underhanded-c.org/
- DINKDINK 10y agohttps://gitian.org/ https://gitian.org/ The bitcoin development community solved the problem of mapping source code to a binary build. Check sums or signatures of binaries is not sufficient. Open source is meaningless if you cannot verify the source maps to the build and you're running critical software with irreversible consequences. E.g. a bitcoin transaction or a dissident being imprisoned from state surveillance eaves dropping on communications.
- andrepd 10y agoYou can build and check against the binaries. What's your point?
- Ao7bei3s 10y agoReproducible builds will fix that, soon.