4 ms·
That’s not a very accurate analogy. The situation would be more like “you can only use a pre-compiled, audited version of OpenSSL”, which makes much more sense.
by yzmtf2008 8y ago
That’s not a very accurate analogy. The situation would be more like “you can only use a pre-compiled, audited version of OpenSSL”, which makes much more sense. Of course you could audit source code as well, but it’s much harder to verify than a binary.
- Hello71 8y agowait, wait, it's harder to audit source code than a binary? wtf?
- yzmtf2008 8y agoI should probably clarify: it’s easier to make sure that a binary is the same as a version that has been audited, whereas with source code, there’s much more uncertainty in the build process.
- pknopf 8y agoWith Yocto, you can audit the recipes (example [0]) being used to build the library. Yocto all generates checksums for all inputs and outputs, caching intermediate build steps, ensuring consistency in the build process. Also, Yocto will not compile anything with your local/native gcc toolchain. It will however use your local gcc toolchain to build it's own gcc toolchain, which it will then use to build all the relative recipes. This again ensures build consistency across platforms/machines. If the argument is purely a "well, I can't audit the produced binaries", I'd argue that you can audit the build system in great detail. [0] https://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta/recipes-graphics/harfbuzz/harfbuzz_1.7.5.bb https://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta/re...
- loup-vaillant 8y agoHow about the following? "Sure, we do use the precompiled binaries. We can even prove it because they have the same hash, and our procedure fails if they don't" How you obtained your binary is immaterial, if you can prove it's the same as the audited one. Surely regulatory people would accept that?