3 ms·
Completely agree that they should understand what’s going on however: It’s sometimes easy to forget that there are various reasons people are less informed. Fo
by merlinsbrain 9y ago
Completely agree that they should understand what’s going on however:
It’s sometimes easy to forget that there are various reasons people are less informed. For people early in the career for example, reading security advice on HN and believing it is not unheard of especially when you have real experts on here who know what they’re talking about.
Something that is “all there is to it” for you is not necessarily the same for someone else. I’m not saying it’s anyones job to inform them; just that it’s better not to speak in absolutes.
If security folks say something, I assume there’s a good reason until I become a security folk myself - it’s one of those fields where being sceptical about everything third-party helps.
My point really wasn’t about the MITM but a there’s always a possibility that a proxy on a public/compromised network can intervene between you and a “secured” website.
Binaries can be verified with checksums to make sure that the artifact hosted on the repository is indeed what you received.
You are 100% correct that you are still trusting the code from the third party developer though!
- ktta 9y ago>My point really wasn’t about the MITM but a there’s always a possibility that a proxy on a public/compromised network can intervene between you and a “secured” website. Same can happen to a binary. >Binaries can be verified with checksums to make sure that the artifact hosted on the repository is indeed what you received Here's the problem. The checksum is usually on the same page the binary is located. Which pretty much defeats the purpose.
- merlinsbrain 9y agoI see, and this was your original point. I guess the only threat there (that I can see) is that the install script can be malicious, but your point was that you’re trusting the owners of the website anyway by downloading their binary and executing their code locally. It can be argued that it’s probably easier to ship malicious code outside the main repository (e.g. in an install script) but I do not have a good counter besides this weak argument. The checksum is indeed usually on the same page and does make it useless in my hypothetical MITM.