3 ms·
Why? These applications are super complex and you can't count on all eyeballs detecting a potential backdoor. And, you don't know if the code in the repo match
by azahk 8y ago
Why?
These applications are super complex and you can't count on all eyeballs detecting a potential backdoor. And, you don't know if the code in the repo matches what you download from the App Store.
- xxs 8y agoThis is a very weak argument, eyeballs do find backdoors. Usually each commit is checked by few people and the introduction of the backdoor is rather obvious. As for not knowing what has been downloading (if someone tempered with), the best approach is compiling it on your own.
- gaius 8y agoThis is a very weak argument, eyeballs do find backdoors Eventually, maybe. How many eyeballs and how long to find Heartbleed?
- Coxa 8y agoThere's a difference between a potential backdoor and a bug. While a lot of eyeballs might oversee a bug, you have to make an effort to design your backdoor to go unnoticed.
- gaius 8y agoGood backdoors are indistinguishable from bugs, for plausible deniability
- zAy0LfpBZLC8mAC 8y agoThe question isn't whether there won't ever be backdoors, but how likely that is, how long they will stay in place undetected, and what the effects on the reputation of the product/project/committer are once they are discovered. Bringing this up as an argument is a sensible as claiming that transparency and democracy isn't any better than a dictatorship because there is still corruption.
- kasey_junk 8y agoCan you cite any commits for any open source software where a back door was attempted to be introduced & code review found it pre-emptively? The reason I ask is that this is an oft repeated claim about open source by developers yet when I talk to security people they don’t seem to care about open source nearly as much. To them inspecting binaries is table stakes anyway. Meanwhile people write backdoors that aren’t obvious for fun. http://underhanded-c.org/ http://underhanded-c.org/
- gcthomas 8y agoSignal has had its encryption code audited by researchers, and the Store binaries are signed by the developer, while the repo offers reproducable builds: you can check for yourself if the downloaded apk from Google Play matches what you built from the repo.
- jillesvangurp 8y agoIf your point is that it is not perfect, you are right. Case in point here is openssl which after decades of usage was so convoluted that people decided to create independent implementations to cut down on the problems that were found in it regularly. You are also right that appstores are a problem. However, one of the nice things they do is using signatures to prevent tampering with the builds. So having a build system that produces reproducible builds and signatures means users can check whether things line up. A bigger problem is the reliance on the phone network for identity. A lot of these chat clients insist on using telephone numbers for identifying users. This has been used to shut down chat networks in countries with telecom operators that are collaborating with governments. If you want to stay secure, most of the chat apps out there are problematic at some level. Signal is one of the very few decent options out there. It is one of the few solutions that has both open source clients and servers and a wide community of people using it and scrutinizing it. With e.g. whatsapp, you are at the mercy of a multinational with a track record of indifference and negligence towards the goal of preserving their user's privacy and, worse, a strong incentive towards doing the exact opposite.