11 ms·
wait, wait, it's harder to audit source code than a binary? wtf?
by Hello71 8y ago
wait, wait, it's harder to audit source code than a binary? wtf?
- yzmtf2008 8y agoI should probably clarify: it’s easier to make sure that a binary is the same as a version that has been audited, whereas with source code, there’s much more uncertainty in the build process.
- pknopf 8y agoWith Yocto, you can audit the recipes (example [0]) being used to build the library. Yocto all generates checksums for all inputs and outputs, caching intermediate build steps, ensuring consistency in the build process. Also, Yocto will not compile anything with your local/native gcc toolchain. It will however use your local gcc toolchain to build it's own gcc toolchain, which it will then use to build all the relative recipes. This again ensures build consistency across platforms/machines. If the argument is purely a "well, I can't audit the produced binaries", I'd argue that you can audit the build system in great detail. [0] https://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta/recipes-graphics/harfbuzz/harfbuzz_1.7.5.bb https://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta/re...
- loup-vaillant 8y agoHow about the following? "Sure, we do use the precompiled binaries. We can even prove it because they have the same hash, and our procedure fails if they don't" How you obtained your binary is immaterial, if you can prove it's the same as the audited one. Surely regulatory people would accept that?