3 ms·
What is your plan?
by AlphaCenturion 4y ago
What is your plan?
- csande17 4y agoFour-part plan is this: 1. For each application and library in the system, maintain a copy of the source code and the scripts necessary to rebuild it. 2. Keep track of the dependency tree of each application and library in the system. 3. If there's a problem with a dependency, update it and rebuild all dependent applications. 4. If I'm using binaries from a vendor (whether that's a Linux distribution or a proprietary software company), the vendor needs to be responsible for (1) to (3). In practice, your package manager will generally implement almost all of (1) to (3) for you. (Newfangled systems like NPM or Cargo usually do it using lockfiles and automated tools like Dependabot.) If you're using dynamic linking, guess what? You still have to do these four things, because even with dynamic linking, there are still problems that can only be solved by recompiling your software. Even if you think reasons like ABI incompatibility or processor bugs aren't compelling, there might be, y'know, bugs in the applications themselves that you've gotta patch.
- arinlen 4y ago> If I'm using binaries from a vendor (whether that's a Linux distribution or a proprietary software company), the vendor needs to be responsible for (..) I'm not even going to bother pointing how unfeasible all your other points are. I'm just going to point this Fack: you do understand this does not work and never worked at any point in time, don't you? Do you understand the explicit reference to perpetually vulnerable systems? Do you realize where it cames from? You only have the power to rebuild the packages you own personally, and even so static libs offer zero ways to keep track of which version went into which build. Once your fantastic panacea starts to rely on your idea to force third parties to follow your personal orders to make new releases under your own personal terms, you should be very aware that you will not get your wish. You'll instead just keep on using the same vulnerability-riddled release. Do you understand the importance and value of static libs? You do not need four-point authoritarian and deeply impractical and unfeasible plans to keep your system safe. With shared libraries you just patch the one lib, and all your system is safe. And again what tradeoff do you want to achieve for this? Nothing?