4 ms·
I'd consider it primarily a source release. Since source is available, of course you should audit it, or at least glance over it before compiling.
by code_duck 8y ago
I'd consider it primarily a source release. Since source is available, of course you should audit it, or at least glance over it before compiling.
- raesene9 8y agoIf the goal was a source release they probably should have posted source + compilation instructions, rather than recommending curl + chmod :)
- nailer 8y agothey did, right underneath.
- nebulous1 8y ago> Since source is available, of course you should audit it, or at least glance over it before compiling. Really? I don't think everybody auditing the source of the apps we use is at all realistic, and I don't think glancing at the source is worthwhile. Barring an organized audit, I think confidence in an open source tools like this just comes with popularity, rightly or wrongly.
- code_duck 8y agoI think it's reasonable to wait for the community to audit it, and to trust that. Popularity tends to include a certain amount of vetting by people who do have time, resources or knowledge.
- raesene9 8y agoThat could happen, but if it did it would very much be the exception rather than the rule :) Heartbleed and shellshock (and others of course but those two have memorable names) very much laid the general case of "many eyes make all bugs shallow" to rest. The unfortunately truth is that a tiny percentage of source code gets reviewed by a competent reviewer. In this case my feeling is that it being crypto+rust the chances are even smaller than usual..
- floatboth 8y ago> crypto+rust Well, security_protocol+rust. The actual crypto comes from https://github.com/briansmith/ring https://github.com/briansmith/ring which just calls hand-written assembly crypto code copied from BoringSSL.
- paulie_a 8y agoThat worked really well for openssl
- ktm5j 8y agoSince source is available, of course you should audit it, or at least glance over it before compiling. You should realize that this is not feasible for everyone as most people are not developers.. and even in the subset of people who both how to write software and (in this case) know rust, how many are really qualified to audit a software project for malicious code or vulnerabilities? I'm a professional developer and I'm certain someone could slip some obfuscated code in a project with several thousand lines of code and I'd never know it.
- code_duck 8y agoThat's why I would wait for other people to find that out, if I can't trust or audit it myself. Agreed that a brand new package from an unknown single developer is more risky. As far as a trap with clever obfuscation, it sounds like any software we use could be vulnerable to that. It could be added as a patch to a seemingly routine update for any of the thousands of packages on your system.