3 ms·
A number of large companies are quietly moving towards reproducible build. Sorry if I cannot name the names. As a side note, reproducible builds implemented in
by ex_amazon_sde 6y ago
A number of large companies are quietly moving towards reproducible build. Sorry if I cannot name the names.
As a side note, reproducible builds implemented in Debian were also useful to spot various other problem: small differences in build environment that would make debugging more difficult.
Sometimes the same application will have different performance depending on the build due to memory alignment, data ordering, cache friendliness.
Finally, the article is making some claims that are, frankly, incorrect:
> Q. It’s easier to audit source code than binaries, and this will make it harder for vendors to hide malicious code.
> I don’t think this is true, because of “bugdoors”. A bugdoor is simply an intentional security vulnerability that the vendor can "exploit" when they want backdoor access.
Adding a backdoor and compiling a new "custom" binary might take 10 minutes and a lot of people in a company could do it and leave no traces.
Writing a "bugdoor", committing it and passing code reviews is very different. You might have to justify why you are touching a product / component / library that might be completely unrelated to your usual work.
Plus, you leave a very clear record of your action, giving up a lot of deniability.
> Q. It’s easier to tamper with binaries than to write a bugdoor, so reproducible builds do improve security.
> I absolutely disagree, every programmer knows how to write a bug or short circuit some logic. Hiding malicious activity in a binary, with a multi billion dollar malware industry determined to find it is more difficult.
This implies that the malware industry is somehow unable to detect a "bugdoor" or unexpected behaviors a runtime but able to detect a change to the binary...
> In addition, once you’ve produced and signed the malicious backdoor, it is not repudiable - you can’t deny you wrote and provided it.
Most organization track source code changes in a VCS but don't require employees to sign binaries with keys bound to each individual. If anything, this makes a point in favor of repro builds.
- TwoBit 6y ago> A number of large companies are quietly moving towards reproducible build. Sorry if I cannot name the names. Thanks, user "ex_amazon_sde"!
- ex_amazon_sde 6y agoI wrote "a number" and I was not referring to Amazon :)