5 ms·
"How do Linux/Mac package managers solve this?" By building their binaries from source and hosting them on their servers?
by wheelerof4te 3y ago
"How do Linux/Mac package managers solve this?"
By building their binaries from source and hosting them on their servers?
- dewey 3y agoWouldn't help if the source code already has the backdoor in there though. Most people would just download and build a tool off GitHub if it has 200 stars and does what they need.
- wheelerof4te 3y agoIt's extremely hard to sneak backdoors in open-source code. Which is one of the reasons why a lot of people promote that openness.
- dewey 3y agoInto a popular repository yes, but into a small tool like that it would most likely be very possible.
- wheelerof4te 3y agoSmall tool = less code to read through. If you want to use that suspicious tool, you should at least take a glance at the source code.
- dewey 3y agoIn an ideal world that would be the case, but people barely read the README or documentation.
- tough 3y agoThat's on their own fault, and on the alternative closed source scenario nobody would be able to read the source without reverse engineering it first
- userbinator 3y agoI did, and on the rare occasion that I need to use a downloaded binary today, still open it in a text editor and scroll through it for a cursory look. Packed -> reject. Bigger than expected -> reject. URLs or other strings, especially obfuscated, not related to expected functionality -> reject. Online AV multiscanners offer a reasonable alternative for those who aren't familiar with this sort of quick-glance RE, although they do have false positives too.
- account42 3y ago> Online AV multiscanners offer a reasonable alternative You're right, (not just) online AV multiscanners are also FUD machines that will happily accept malicious programs but reject anything well crafted and optimized because it doesn't like exactly like the shit MSVC craps out with default settings.
- userbinator 3y agoIt's extremely easy to sneak backdoors in open-source code that contains automatic update functionality.
- deleted 3y ago[deleted]
- pixl97 3y agoGithub stars are also complete bullshit that can be gamed itself.
- _xivi 3y ago>> By building their binaries from source and hosting them on their servers > Wouldn't help if the source code already has the backdoor in there though I'm not sure if you're aware but random tools don't just spawn in official package repositories overnight. There's a vetting process, for both new packages and new maintainers. Also in established distros, packages don't get accepted to official repositories unless it's a critical and highly demanded one. So yeah, any software can have vulnerabilities, regardless of OS. But stray tools and dubious actors, are pretty much a solved problem in linux distros. The situation on Windows is laughable in comparsion. No need to spread FUD.
- zx14 3y agoThe maintainers can be compromised though. Is every single version of every single "vetted" package / maintainer also vetted?
- _xivi 3y ago> The maintainers can be compromised though. Is every single version of every single "vetted" package / maintainer also vetted? Pretty much, packaging is not a brainless process. One of the effort that specifically target this is the Reproducible builds project [0], along with many other security measures set by each distro. There are also usually multiple testing and updates rolling stages. The best evidence of how effective these measures is its actual reputation and record on the ground. [0] https://reproducible-builds.org/ https://reproducible-builds.org/
- 3np 3y agoThis is a good thing to consider when picking Linux distros. Who are the maintainers, is maintenance done in the open, do they enforce reproducible builds, how is review process done, what are requirements for mainters/packages/releases? You also have the option of building from source yourself. Some package managers and distros (Gentoo, NixOS, Guix) do this for you. This is BTW the main reason I wouldn't use derivate distros for anything serious. Debian's generally trusted in the community - their slow pace come from risk-aversiveness.
- 3y ago