3 ms·
Honestly, I think the reliability of those packages are not guarded by these people, but rather by the corresponding communities of those packages. If one of t
by SCLeo 7y ago
Honestly, I think the reliability of those packages are not guarded by these people, but rather by the corresponding communities of those packages.
If one of the community failed to secure its package from malicious people, these people at debian are not going to be able to stop it.
Thus, those packages are still guarded by a huge community.
- umanwizard 7y agoWhy do you think this? OSes like Debian don’t just pull packages from upstream automatically. Packages have actual maintainers affiliated with the OS, not the upstream community, and it’s those maintainers who build packages for the OS repos.
- ryacko 7y agoNot entirely true, Debian actually made OpenSSL less secure once: https://www.debian.org/security/2008/dsa-1571 https://www.debian.org/security/2008/dsa-1571
- umanwizard 7y agoThis doesn’t contradict my point. I never said that Debian maintainers are more trustworthy than upstream 100% of the time. I merely said that Debian packages are built, uploaded, and vended by Debian package maintainers, not by upstream. Whether that makes them more trustworthy or less is a different question.
- oefrha 7y agoMy software is packaged by Debian, and the update process is me notifying the Debian Developer (DD) responsible for the package of the new version => said DD pulling the new tarball from GitHub. Pretty sure no one’s gonna notice until after it’s pushed to Debian FTP if I introduce some subtle malicious code. Point is DDs don’t review version deltas for the most part, so when the upstream is compromised, they add little to your defense (other than security by outdatedness, I suppose).
- umanwizard 7y agoSure, but a very long time will pass between it being uploaded and being merged into stable, so there is a lot of time for people to discover your malicious code. It is not like npm or crates.io where you can just upload whatever random code you like and people will start picking it up immediately. But it’s not foolproof, sure, I agree with that.