4 ms·
What if someone gives you a binary that they claim is built from a particular source code? If you don't decompile it, how do you know if that's true or not? O
by biggieshellz 4y ago
What if someone gives you a binary that they claim is built from a particular source code? If you don't decompile it, how do you know if that's true or not? Or what if you can't trust your compiler (a la https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html)?
- intelVISA 4y agoI could never trust a bin I didn't build myself (with my own C compiler ofc).
- arjvik 4y agoDid you build that C compiler yourself? Using what compiler? Unless you bootstrapped it from a handwritten assembler, you'll need to consider the attack outlined in Reflections on Trusting Trust
- intelVISA 4y agoI did but I foolishly relied on GCC before it was self-hosted now I guess I should scrap the whole thing and build by hand.
- pxc 4y agoThere's actually someone out there who has done some impressive work on this, believe it or not! https://savannah.nongnu.org/projects/stage0/ https://savannah.nongnu.org/projects/stage0/
- JCWasmx86 4y agoReproducible builds. Sure not every project can be built in a reproducible manner, but it at least reduces the chances of getting shady binaries
- pxc 4y agoCheck out `guix challenge` for a concrete example of how tidily this can be done with a system that supports reproducible builds well! https://guix.gnu.org/manual/en/html_node/Invoking-guix-challenge.html https://guix.gnu.org/manual/en/html_node/Invoking-guix-chall...