3 ms·
Agreed. However, this is unfeasible/impractical. Ain't nobody got time for that. Are there any commercial or non-profit organisations that maintain lists/repos
by elnygren 9y ago
Agreed. However, this is unfeasible/impractical. Ain't nobody got time for that.
Are there any commercial or non-profit organisations that maintain lists/repos of audited and trusted software with their checksums? It seems like there would a demand for a package manager like that.
I suppose some Linux distros have pretty OK repositories?
I wouldn't trust npm, pip, gem etc. though.
- shakna 9y agoThat's the second half of the quote: > Or get it from a trusted source that did the review for you. Incidentally, curl has been reviewed by the Mozilla Secure Open Source project [0], who maintain lists of audits which include checksums within the report. Maybe you're looking for something similar? [0] https://wiki.mozilla.org/MOSS/Secure_Open_Source https://wiki.mozilla.org/MOSS/Secure_Open_Source
- pjmlp 9y agoWhich version? In order for this process to be truly secure, every single software version needs to be audited.
- Xylakant 9y ago7.50.1 The repost can be found here https://wiki.mozilla.org/images/a/aa/Curl-report.pdf https://wiki.mozilla.org/images/a/aa/Curl-report.pdf You don't have to do a full audit on each version, auditing the deltas should be fairly comprehensive. Now, there could be some malicious code hidden that gets triggered by a begnin change, but otoh, no audit ever will guarantee full security.