5 ms·
You can say the same thing about the entire Linux stack
by 0x0nyandesu 5y ago
You can say the same thing about the entire Linux stack
- mPReDiToR 5y agoUnless you're using LFS, of course. The problem you describe isn't Linux, it's Linux Distributions. Where would you draw the line? Source packages are available, and if the binaries don't match the code a distro would soon be outed a la "many eyes" thinking. We have to trust some or none. Get the top off that chip, see if the factory put an extra core in for the NSA (IME).
- asddubs 5y agoany operating system, really, if you want to play that game
- mid-kid 5y agoNot really, individual package developers don't have as much inmediate control over the repository's state as they do with NPM. Packages go through a review by one of the trusted developers and sometimes automated QA and testing (including as of late reproducibility testing, i.e. does the source match the binary?), before being uploaded to the repository. If you can't trust the team behind the distro, then sure, your supply chain is compromised, but it's significantly less likely for a single package developer to cause any damage, as all the big distros have rather extensive policy and procedures to prevent such things.
- 0x0nyandesu 5y agoI use Gentoo which uses portage the package manager and the way portage works is it pulls source then compiles. Source is rarely checked by everyone. Small packages exist as well. Many Linux distro simply barrow binaries from "trusted" sources. The entire eco system is really a deck of cards.
- deleted 5y ago[deleted]
- ThrashBeard 5y ago> Many Linux distro simply barrow binaries from "trusted" sources. The crappy ones maybe. Proper distros build everything from source.
- marcus_holmes 5y agoThis is a false equivalence brought up every time anyone mentions how vulnerable the npm/gems/pip ecosystems are to supply chain attacks. Linux code is always reviewed before deployment, goes through many eyeballs, people are careful about this. The same is not true of npm, or any of the other services (as this event clearly shows).
- 0x0nyandesu 5y agoEh that's not true. I use Gentoo so trust me most things are run by little dictators of their own little fiefdoms. I'm talking about not just the kernel but all the various other things from libraries to servers to tools and everything in between.
- marcus_holmes 5y agoOK, but none of those little fiefdoms are "Linux".
- 0x0nyandesu 5y agoI literally said the Linux stack which includes everything from the kernel to init to libs. You can't run just the kernel.
- marcus_holmes 5y agoIt's still a false equivalence. You'll agree that all the important bits of the Linux Stack are audited and reviewed by multiple people, right?
- 0x0nyandesu 5y agoLol hell no. You're joking right?
- smorgusofborg 5y agoParts of the Linux stack equivalent to colors and faker are carefully audited and reviewed by multiple people? That sounds to me like elevating them to important bits in a false equivalence.
- goodpoint 5y agoNo, serious Linux distributions audit their code.