4 ms·
With regard to the current, warrant-backed intrusion method: the default configurations of most Linux distros are far more secure than the default configuration
by HedgeMage 15y ago
With regard to the current, warrant-backed intrusion method: the default configurations of most Linux distros are far more secure than the default configuration of any version of Windows. Keep up with your browser updates, don't run anything you don't trust, and you should be fine.
With regard to the possibility of back doors in future software...
Hackers, as a culture, are pretty anti-Big-Brother -- I can't imagine any of us voluntarily distributing back-doored packages. If we distributed compromised code, one of our peers would catch it before too long in the case of any but the most obscure packages. The thing is... when might it not be voluntary?
As far as American courts are concerned, source code is speech, compiled binaries are not. So, the government could conceivably force distributors of binary software to comply with a back-door policy, but they could not restrict the distribution of uncompromised source code. (This is why source-based distros can distribute things like DVD-decrypting software, while binary distros leave you to acquire it elsewhere: the distribution of source code is unrestricted.)
The only binaries on my laptop I haven't compiled myself are my video driver (I'm giving you dirty looks, NVIDIA) and the blob for my wifi driver (I'm giving you dirty looks, FCC). I'd like to get rid of both of them -- I'd absolutely pay more for a decent video chipset that didn't require closed-source anything. The wifi blob is the fault of the FCC -- no one in the US can legally distribute wireless hardware that could have its frequency usage changed by the owner. Many wifi cards get reverse engineered at some point, making the binary blob unnecessary, but manufacturers are legally prohibited from aiding in the process of creating completely open-source drivers.
Compromised source code coming from a tool's creator is both unlikely, and hard to pull off for long. Compromised binaries are more likely, but there are plenty of distros not based in the US which would have more leverage in resisting such demands (of course we don't know what their own countries are requiring of them). Getting source code with an "added" back-door (i.e. from a third party rather than the code's maintainers) is easy to avoid if you only use signed code -- make sure to watch for packages that stupidly download code for their dependencies during build without checking signatures instead of using what's already on your system.
As for those drivers with binary blobs -- until consumers become more resistant to using them, they aren't going anywhere.
- mattgreenrocks 15y agoIIRC, ath5k does not need a binary HAL any longer. There is also the madwifi-free branch which has the HAL in source form.