4 ms·
So what you are saying is that if you never install closed source software, you will never (intentionally) install malware because you define all malware as clo
by anon1385 9y ago
So what you are saying is that if you never install closed source software, you will never (intentionally) install malware because you define all malware as closed source. This is a meaningless tautology. The advice you are giving is both objectively wrong and actively dangerous.
Firstly not all security issues involve installing 'malware'. Take heartbleed; a major security vulnerability in open source software. To be hit by that you didn't need to install any non-open source software. You could have had the most pure and open stack of software and hardware ever created and it would have made no difference because the flaw was an information leak that didn't involve installing software or even unintended remote execution of code. That bug was due to the existing already installed open source code copying past the end of a buffer. Similar information leaking bugs could feasibly exist due to CPU bugs or compiler bugs or undefined behaviour in the code etc (i.e. all sorts of ways that don't involve installing malware and aren't even obvious from reading the code).
Secondly, even exploits that do involve "running malware" are very often not because the user intentionally installed malware. They happen because the user did something like download and decode an image file which took advantage of a vulnerability in their (open source!) image decoding library to execute code on their machine. Again in this scenario it doesn't matter that the user would only ever intentionally install open source software, because the malware was executed unintentionally when they performed an activity they didn't expect to lead to code execution (viewing an image).
E: These CPU issues are fundamentally timing attacks that leak information. I don't need to execute code on your computer at all to run a timing attack against you that leaks valuable information - I can do it by sending packets of pure data and don't need to be able to execute arbitrary code on your machine at all. Side channels like timing attacks don't necessarily require any kind of code execution on the target machine (although obviously having a high precision local timer makes it easier). This isn't just theoretical, it has been demonstrated in reality. For example see this paper[1] which demonstrates doing timing attacks against a browser to reveal the users browser history without the need to execute javascript at all. It's all done by sending CSS, which isn't code.
[1] https://www.nds.rub.de/media/nds/veroeffentlichungen/2014/07/09/DSN_paper.pdf https://www.nds.rub.de/media/nds/veroeffentlichungen/2014/07...