2 ms·
> As an example of where this central point of failure becomes problematic, attackers can modify a package to include malware in what is known as a digital supp
by nmadden 5y ago
> As an example of where this central point of failure becomes problematic, attackers can modify a package to include malware in what is known as a digital supply chain attack. What we really want, and what no package manager can give us today, is reproducibility.
Tavis Ormandy of Google Project Zero wrote a very good debunking of this supposed security benefit of reproducible builds: https://blog.cmpxchg8b.com/2020/07/you-dont-need-reproducible-builds.html https://blog.cmpxchg8b.com/2020/07/you-dont-need-reproducibl...
- pwm 5y agoRelated: https://www.tweag.io/blog/2020-12-16-trustix-announcement/ https://www.tweag.io/blog/2020-12-16-trustix-announcement/
- tomberek 5y agoThat article is merely making the argument that reproducibility on its own does not improve security. This is clearly true. Anyone can also claim that code-signing does not improve security because "well, you have to trust either this blob of software, or this certificate blob, or this signature, what's the difference?" The difference is when you start to compose these parts into a larger system. Dependable qualities of a system (eg: a specific hash function is one-way, or that specific problems are hard/easy to solve) can be used to create the security properties you want. I doubt Tavis is saying that builds should not be reproducible; just that it is not going to provide security on it's own in a trivial manner. I'd argue that reproducibility can help create secure systems with properties otherwise unobtainable (or difficult).
- nmadden 5y agoI’m sure reproducible builds has some small part to play in supply chain security, but I think it is massively over-emphasised. My own view is that all of supply chain security is somewhat of a red herring anyway. I don’t want to have to trust software vendors at all, whether I think they may have been hacked or not. I shouldn’t have to trust log4j or any other legitimate dependency. And I shouldn’t have to audit the source code (or delegate that) to find out if I should trust it. We run all software with far too many privileges by default. Kate Sills at Agoric had a great article about this a few years back (Medium, sorry): https://medium.com/agoric/pola-would-have-prevented-the-event-stream-incident-45653ecbda99 https://medium.com/agoric/pola-would-have-prevented-the-even...