4 ms·
Ubuntu, debian, armbian etc all have pipelines, build processes to create an image file where the users can install. The processes where one can compile/build/p
by umbcorp 4y ago
Ubuntu, debian, armbian etc all have pipelines, build processes to create an image file where the users can install. The processes where one can compile/build/package are already there (signing the image might require more steps with access to keys). Documentation and the tooling for such processes can be improved and made more user friendly.
With the evolving supply chain attacks, US Government advised companies to better understand their software supply chains. With transparent and repeatable builds this goal would be much more simple using the approach documented above.
We can innovate on more ideas for making more transparent software. We can have signed dependencies, pre-built trusted (signed, hashes) dependency chains.
- ivan_gammel 4y agoYou cannot really expect that every user will have sufficient expertise to understand how an operating system works. Today not even technical users can do it without investing considerable effort. Security only explains why _some_ people should be able to understand how software works, and this is a different story. You do not need to make software open source or free for that, there can exist entire spectrum of various licenses and accesses. This is what I mean by delegating the work to institutions: you let someone you trust to audit the code for you. This can be a dedicated team in your company, a 3rd party expert or a government agency, the important part is only those people really need access to the code, because only they can understand it.
- datadata 4y agoYou do not need to understand the entire operating system to benefit from open source. Open source can enable an end user to fix or at least report a narrow issue.
- ivan_gammel 4y ago>Open source can enable an end user to fix or at least report a narrow issue. This is a very small subset of end users that can do that and will want to do that. Even software engineers may not dare to touch the code and seek for workarounds or ways to report the bug with less effort instead. The programming language and APIs can be unfamiliar, there can be lack of context etc. The distance between general computer science literacy and ability to read the code of a large product is very big - experts often tend to underestimate it. For the majority of other people value of this possibility is literally zero: they would prefer to have a warranty from vendor. There's very little consolation for them in having weak guarantees from community of volunteers that discovered bugs will be some day fixed.