6 ms·
I didn't like few implications author makes. > One of the biggest parts of the Free and Open Source Software definitions is the freedom to study a program and
by viktorcode 5y ago
I didn't like few implications author makes.
> One of the biggest parts of the Free and Open Source Software definitions is the freedom to study a program and modify it; in other words, access to editable source code.
You don't have to have FLOSS-compatible open source license to run security audits on the code. For instance: Microsoft allowed government entities to check Windows security-related source code for many years. Just having access to the code is enough for audits, regardless of the license.
> One such reason is that source code is necessary to have any degree of transparency into how a piece of software operates, and is therefore necessary to determine if it is at all secure or trustworthy. Although security through obscurity is certainly not a robust measure...
If code is not open sourced it doesn't mean security through obscurity is employed. It simply means there's no public access to the code. This is a very common misconception.
- deknos 5y ago> Just having access to the code is enough for audits, regardless of the license. No. who guarantuees that the code is the one, which is compiled to the binary you are running?
- pabs3 5y agoYou can use Reproducible Builds to compile the source code and get the exact same binary: https://reproducible-builds.org/ https://reproducible-builds.org/
- deknos 5y agowith opensource you can do this. but with closed source like from microsoft, that is not automatically given.
- ben_w 5y agoIn the context of “government agencies”, they can just order Microsoft to make it possible, if they care. In the case of Windows for Warships[0], one of the arguments (if they absolutely had to use Windows and nothing else) might be something like “Dear Mr. Gates, if you don’t empower us to do our job, we can’t guarantee that North Korea won’t retarget our nukes at your face. Sincerely, the Royal Navy.” [0] https://en.wikipedia.org/wiki/Submarine_Command_System https://en.wikipedia.org/wiki/Submarine_Command_System
- pabs3 5y agoYou could have some sort of reproducible-builds escrow organisations; for eg release your code to them, they would do a build and publicly sign hashes of the build they produced.
- consumer451 5y agoApologies for my ignorance here, but what is the current "market penetration" for reproducible builds? As in, if you combine all sources of FLOSS binaries, what percentage of total binaries follow use this system? Looking at the site you linked, am I to correct that this is still early days in actual implementation?
- pabs3 5y agoThere are lots of open source distros involved in the Reproducible Builds project and many of them are running CI to identify potential sources of non-determinism and identify regressions etc. For example currently 83.4% of Debian unstable amd64 is reproducible on the CI system (which builds twice in two different build environments and compares the builds). The variations tested for unstable are more than those for bookworm/bullseye though, so the numbers aren't easily comparable. Also, For Debian at least, there is some work on reproducing existing binaries from the archive using the Debian snapshot service, but I'm not sure where that is at. https://reproducible-builds.org/who/projects/ https://reproducible-builds.org/who/projects/ https://reproducible-builds.org/citests/ https://reproducible-builds.org/citests/ https://tests.reproducible-builds.org/debian/reproducible.html https://tests.reproducible-builds.org/debian/reproducible.ht... https://tests.reproducible-builds.org/debian/index_variations.html https://tests.reproducible-builds.org/debian/index_variation... Personally I find the Bootstrappable Builds project way more important and interesting. They are aiming to go from less than 1000 bytes of audited machine code (not assembly) plus all the necessary source code all the way to a full Linux distro. They are impressively far along already. They use multiple techniques for bootstrapping higher levels, including writing new implementations of languages written in other languages, using old versions of languages that were written in other languages etc. Some details here: https://bootstrappable.org/ https://bootstrappable.org/ https://github.com/fosslinux/live-bootstrap/blob/master/parts.rst https://github.com/fosslinux/live-bootstrap/blob/master/part... https://github.com/oriansj/talk-notes/blob/master/live-bootstrap.pdf https://github.com/oriansj/talk-notes/blob/master/live-boots... Edit: some talks about bootstrappable: https://github.com/oriansj/talk-notes/blob/master/talks.org https://github.com/oriansj/talk-notes/blob/master/talks.org
- mrjin 5y agoOkay, event you are assured that the source code you see are the origin of the binary you run, still no one can guarantee you there are no security concerns. The reason is simple: software are written by human, at best they were created with good will and there were due diligence. But doesn't matter how careful the developers and the auditors(if there were any) were, there are for sure security related bugs. Making it worse, there have been and going to have lots of deliberately planted backdoors. Given the complexity of the software and the cost of auditing, even if you have all the original source code, most likely you are unable to reveal planted backdoors. And if you indeed found something, how can you tell whether it was bug or a backdoor?
- pabs3 5y agoThis part of the subthread was about ensuring the binary you run was built from the source code you have. Of course there could be bugs in that source code and or bugs in the resulting binary, so you have to audit both of them and fix anything suspicious.
- kube-system 5y agoThere are engineering solutions to this, as another comment mentioned. But, you don’t necessarily need an engineered solution to it, either. Trust can be established through non-engineered means.
- deknos 5y agotrust can be established otherwise, but with software it is extremely hard to notice that trust violation for closed source software
- DonHopkins 5y agoIf you're really that paranoid that you believe such conspiracy theories, then simply compile and run the source code they provide, and run that instead of the binary they also provide. But you have to admit, it's a pretty implausible conspiracy theory, since it would be so straightforward for you to do that. Because they're literally providing you the source code WITHOUT the backdoors, which you believe they don't want you to compile and run.
- deknos 5y agohow can i compile microsofts code? and there are easily systems which are so complex if you compile them the wrong way, you get other behaviour or more bugs. and it may be also human error, not a conspiracy theory. if you do not have the source code and the recipe to build it yourself than you can not guarantuee that the inspected sourcecode (which was given to you either by disk or by a datablob over the internet) is the binary which you are currently running on your windows. hell, perhaps they shipped an update which broke an security measure, and the update was shipped after you inspected the source.
- kube-system 5y agoYep, proprietary software can even be source available. This is not even uncommon with interpreted languages. It’s just easier to enforce compliance by withholding it.
- pwdisswordfish9 5y ago> For instance: Microsoft allowed government entities to check Windows security-related source code for many years. Just having access to the code is enough for audits, regardless of the license. You don’t need a FLOSS license to audit the code. You just need the clout that comes with being a government able to launch meaningful antitrust action. Easy-peasy!
- phendrenad2 5y agoAnother thing people forget is that reverse-engineering is easily accessible to a determined actor. Even if Microsoft hadn't released source code to schools and governments, they could just reverse-engineer it through decompilation tools like Ghidra.