5 ms·
I think your judgment is too harsh. Very few software deployment systems make it possible for binaries to be independently reproduced from published sources by
by lfam 9y ago
I think your judgment is too harsh.
Very few software deployment systems make it possible for binaries to be independently reproduced from published sources by the public. AFAIK, it's limited to systems like Nix, Guix, recent Debian, and other participants in the Reproducible Builds project.
However, even within those systems, if you are downloading a compiled binary instead of building it yourself, how can you be sure that you get the "right" binary every time? Does the binary download system periodically "challenge" the binary provider by building from source and comparing with the downloaded binary? If so, does it report its findings anywhere?
It seems to me that even within a software deployment system that enables users to reproduce binaries, you still end up trusting whoever runs the deployment system, because there are no methods of challenging the reproducibility in a meaningful way. The systems I mentioned above sign the binaries, which means that you implicitly trust the holder of the signing key to send you the right binary. But it doesn't mean anything about the relationship of the binary to some source code.
Having said that, if I am using some program by downloading binaries, I am trusting whoever provides the binaries. If I trust them, then a source code audit is valuable to me, even though I can't be sure the compiled binary is related to the source code.
- huhtenberg 9y agoThere's NO value in 3rd party vouching for the security (read, quality) of some specific version of the software, because this opinion will be rendered null and void with the next software update. There is some value in 3rd party verifying the system design (the architecture, the protocol, etc.) and general engineering practices in the company, but this still hinges on the need to trust this company not to be (or being coerced to be) malicious. TunnelBear hasn't established the latter, so - yes, there's little to no value in former. There is some marketing value in it though. PS. Zimmerman's original secure VoIP project was rooted in the idea of reproducible builds. It was open source, but with a license that prohibited any use except for verifying binary builds. It was 20 (?) years ago.
- lfam 9y agoRegarding Zimmerman's VoIP, Tarsnap does the same thing. The client source is available but you aren't allowed to use it for anything except building the client for the Tarsnap service.
- michaelmior 9y ago"NO value" is a huge stretch IMO. Sure, it's entirely possible for gaping security holes to be introduced in future releases, but if past versions have been consistently vouched for as secure, that's still going to increase my confidence in future versions being secure. Or if I'm paranoid, then where possible I can just stick to a specific version which has been vouched for as secure.