6 ms·
Open source is where you don't have to apply guesswork to find out what a suspicious looking piece of software is doing on your computer.
by sdfjkl 5y ago
Open source is where you don't have to apply guesswork to find out what a suspicious looking piece of software is doing on your computer.
- AussieWog93 5y agoNope, instead you have to apply guesswork to figure out why an apt-get call accidentally uninstalled your desktop environment. :P
- oynqr 5y agoPretty sure there was no guesswork involved in finding out why that happened, since it was resolved so quickly.
- caslon 5y ago"One distribution using one package manager is bad when piloted by an incompetent YouTuber who ignores multiple warnings. Therefore, all of free software is bad."
- AussieWog93 5y agoIt's more than just Linus's experience with Pop OS. So many (consumer-focused) FOSS products have huge, obtuse quirks in them that prevent their widespread adoption, and uber-tech-literate people tend to overlook this because they really want to believe that FOSS can succeed. In reality, a lot of these quirks come about because of the non-commercial nature of the projects[1]. When a business produces software, the aim is to get as many people as possible to use it. This means a smooth (enough) user experience or death. For software written by volunteers, the aim is to (generally) satisfy the intellectual curiosity of the people writing it. This means huge issues for users, and QA in basically all forms, are overlooked in favour of working on cool/interesting things for developers. [1] Yes, I know commercial FOSS exists. I run a reasonably large commercial FOSS project myself. However, the overwhelming majority of FOSS projects out there are volunteer-led and run.
- bee_rider 5y agoWho said free software was easy to use? It just reduces guesswork. It is often the case that precise tools both enable and require a little more understanding on the part of the users.
- bigDinosaur 5y agoWhile there's some truth here, you're underestimating the amount of great open source software that's easy to use. You just don't think of it, and it's likely heavily used by commercial companies. Also, terrible obtuse quirks are certainly not unique to FOSS products. Go ask someone who deals with, I don't know, the software used to run hospitals and healthcare systems (electronic health records, or EHR's) as but one example.
- npteljes 5y agoNo. Widespread adoption is hindered of the status quo that Linux is not the default OS on the PC platform. If governments used Linux internally, mandated that schools teach Linux and Libreoffice, and the Windows bundling thing hadn't happen, and especially if all this happened 15 years ago, the landscape would be vastly different. Linux wouldn't have fewer quirks, maybe it would have more, but nevertheless people would use it because that would make the most sense to them. This is the only thing that matters, not user experience, not the goal of the software, but things that are orthogonal to the software: its integration into society.
- charcircuit 5y agoapt deciding it should yeet essential packages is not a new thing and has happened many times to many people.
- caslon 5y agoApt is a terrible, single package manager.
- caoilte 5y agobeen using debian derived OSes 22 years and never had any problems. Dual boot Windows has permanently BSODed multiple times and required a reinstall. You can do stupid things in Linux, but if you stay on the rails (I only upgraded to Ubuntu 20.04 last week) you're fine. Windows will just mess your system up every so often without you even doing anything except installing the updates it tells you to.
- SanderSantema 5y agoAlthough you could make this argument in this context I don’t think it is valid. I’m quite certain that someone who’s trying to figure out what some obscure service is doing on their machine would be able to use `apt-get` perfectly fine and wouldn’t ignore any all-caps warnings.
- npteljes 5y agoI'll take that every day. Because it's not like proprietary doesn't fuck itself up. For an anecdote, I had a laptop with Win8 preinstalled, and Update just wasn't working one day. The solution? Scouring the internet to find a Microsoft executable that fixed update. How? We'll never know. Because we're not meant to.
- dylan604 5y agoOr the MS update that nuked people's Documents folder?
- jthrowsitaway 5y agoAh yes, gotta love the mystery .exe "fixers" that are sometimes associated with KB articles.
- StreamBright 5y agoOr how Exim ended up on my system when I wanted to install a command line tool that does not require email sending (even if it required why on earth would anybody build such package dependencies).
- kop316 5y agoI'm confused. `apt-get upgrade` doesn't remove packages. `apt-get dist-upgrade` tells you what packages it will remove and has you confirm that you want those packages removed before you proceed. https://www.debian.org/doc/manuals/apt-guide/ch2.en.html https://www.debian.org/doc/manuals/apt-guide/ch2.en.html What guesswork is needed?
- AussieWog93 5y agoIt was a reference to an infamous incident where Linus Sebastian accidentally removed his DE when trying to install Steam via APT.
- _Algernon_ 5y agoYou only have to guess if you ignore the obvious warning and type "Yes, do as I say" indiscriminately. I think that's fair.
- prmoustache 5y agoUnless you blindly launch all apt-get call with the -y command it will ask you for confirmation before uninstalling anything. If you say yes, it is not an accident but 1. your own decision 2. it is easily reversible.
- smoldesu 5y agoSure thing, Linus...
- pjmlp 5y agoIndeed, only to learn about all the programming languages, libraries and communication protocols used in the system, and then they might understand what is happening.
- SanderSantema 5y agoWhereas on closed source you’d have to do all of that and probably a good deal of reverse engineering on top of that. That’s unfortunately not something which it necessarily makes any easier, but rather a lot harder.
- pjmlp 5y ago
- canadaduane 5y agoThe difference here is "[Apple] authorized people who are skilled in the art" vs "anyone skilled in the art" of programming can tell others what it does.
- StreamBright 5y agoYeah my mother really likes checking out what is going on with these pesky opensource services. She sometimes goes to Github to read the code, while at it she quite often finds bugs, sometimes even security bugs. I am so glad we have a way to understand what is going on using opensource software. On the other hand all my blackhat friends have a really bad time with closed source software. This is the primary reason black box security testing is dying.
- dmitriid 5y agoExcept it's been proven again and again that this is not even remotely the truth. The number of people who can properly analyse complex software to uncover what it actually does is a line asymptotically approaching zero. While OpenSSL is an overused example, it still remains a good one.
- rosndo 5y agoAnd the people who can do so are usually the same people who’d be perfectly capable of analyzing binaries directly. Besides, you’ll never know if the code you’re looking at abuses some compiler quirk without studying the binary.
- bee_rider 5y agoSomebody should tell the folks designing high-level languages that their code is no easier to analyze than a binary, I guess.
- Ensorceled 5y agoThe person you are responding to is specifically talking about looking for exploits that are hidden behind compiler bugs or obfuscated by language features. So you're missing the point, I guess.
- dangerface 5y agoDebugging C is usually done in assembly so I guess they know.
- dmitriid 5y agoLevel of the language has little to do with the complexity of code. - a modern OS has anywhere upwards of 50 million lines of code (Linux kernel alone is ~30 million lines of code) [1] - a modern browser is anywhere upwards of 30 million lines of code [2] - there are over 3.5 million individual packages available for the various Linuxes [3] And so on. The pretence that there are people and resources readily available to analyse those sources, and understand them well enough to uncover complex vulnerabilities is just that: a pretence, a myth. As evidenced by high-profile bugs that existed in popular codebases for years. Does the availability of source code make analysis somewhat easier? Yes. There's a difference though between reviewing left-pad on GitHub and auditing OpenSSL, for example. There are thousands of people who can do the former, and perhaps 5 who can do the latter. That is why "the number of people who can properly analyse complex software to uncover what it actually does is a line asymptotically approaching zero". [1] https://www.linux.com/news/linux-in-2020-27-8-million-lines-of-code-in-the-kernel-1-3-million-in-systemd/ https://www.linux.com/news/linux-in-2020-27-8-million-lines-... [2] https://www.openhub.net/p/chrome/analyses/latest/languages_summary https://www.openhub.net/p/chrome/analyses/latest/languages_s... [3] https://repology.org/repositories/packages https://repology.org/repositories/packages
- saagarjha 5y agoYou do know that you can peek at closed source binaries and figure out what they do? It’s not even all that hard in this case and it would quickly tell you what the software does, assuming it’s not intentionally trying to cloak its behavior, which it is not in this case.
- SanderSantema 5y agoEither way, it’s easier if you’ve got the source code as well.
- superasn 5y agoDefinitely right about that. Maybe some user can be unaware of what is happening with OSS, but the community as a whole will always have accurate information of what is what (unlike this case where everyone is guessing).
- dmitriid 5y ago> but the community as a whole will always have accurate information of what is what OpenSSL audit would like to have a word with this mythical community. log4j vulnerability, too.
- deleted 5y ago[deleted]
- BeefWellington 5y agoThere are a few big problems with these examples. For starters, the obvious implied suggestion is that these types of vulnerabilities don't exist in commonly used closed-source systems. That's been proven hilariously false time and again. Secondly, commercial vendors have seen fit to adopt opensource where it suits them in order to take advantage of (and offload responsibility for) what these components do. You're effectively saying "Open Source community doesn't have accurate information because look at X and Y" and ignoring that "X and Y" were also not discovered to have problems by any closed-source using dependent commercial entities.
- dmitriid 5y ago> the obvious implied suggestion is that these types of vulnerabilities don't exist in commonly used closed-source systems I never implied that, obviously or not. > Secondly, commercial vendors have seen fit to adopt opensource where it suits them in order to take advantage of Commercial vendors adopted opensource due to lower cost of ownership, not due to perceived lack of problems or because "community knows exactly what is what"
- dx034 5y agoNo, the only protection against that is to block all outgoing connections that aren't on a white list. Most servers I have work this way. It's annoying at times but lowers the risk of some shady software/library talking home to ~0%.
- rosndo 5y agoYou know, you don’t need the source code to tear a binary apart in IDA.
- dangerface 5y agoLinux package managers are great I haven't had to build a program from source in years. But how do I know the source code I check is the binary my machine runs? Even if I build from source I could have a malicious gcc that takes clean source and outputs a malicious binary. Unless you are running jit or something you can't really know what your computer is running even if you use open source.
- ben-schaaf 5y agoYou can check whether the binaries you have are produced by the source if you have reproducible builds, see https://wiki.debian.org/ReproducibleBuilds https://wiki.debian.org/ReproducibleBuilds.
- rootusrootus 5y agoOn the other hand, you alone are responsible for all the little pieces of software that are part of your Linux system. People running MacOS have willingly given over to Apple the guarantee that Apple-provided MacOS software is not doing anything nefarious. The assumption being that 1) there are enough people capable of detecting malicious behavior that it will get caught, and 2) Apple has a very strong vested interest in maintaining their cred as a privacy-focused company. It is certainly a trade off, and everyone will have their own reasoning. There is no objectively correct answer.
- sdfjkl 5y ago> given over to Apple the guarantee that Apple-provided MacOS software is not doing anything nefarious That depends on your definition of nefarious.
- rootusrootus 5y agoI will grant that many (I would go so far as saying most, and to a very rough approximation, all) users do not have the same purist attitude towards privacy that is common on HN. Metrics on app usage and such would be seen as nefarious here but the average user doesn't care at all.