3 ms·
It's always been surprising to me how little people seem to care about the provenance of their images. It's even more surprising that infosec isn't forcing deve
by patrick451 3y ago
It's always been surprising to me how little people seem to care about the provenance of their images. It's even more surprising that infosec isn't forcing developing to start their images `FROM scratch`.
- w-ll 3y agoAre you compiling you os distro's `FROM scratch`? Ther's always a certin level of trust, and for many, docker containers are just as trusty as distros from trusty orgs or volunteers.
- patrick451 3y ago> Are you compiling you os distro's `FROM scratch`? As a matter of fact, yes.
- rnimmer 3y agoThere once was a man named Terry Davis...
- w-ll 3y agoI imagine anyone with a BA in CS has wrote a OS from scratch. How many systems on chips are in a moderen computer, not the main system and cpu, but every little chip and controller, the boot system, every board seems to have a little OS. In regards to security, its all about analysing risk and trade-offs. For me using containers from known vendors is a risk im willing to take.
- viraptor 3y ago> I imagine anyone with a BA in CS has wrote a OS from scratch. Not even close. Very few courses require anything that advanced and only some of those are non-optional.
- jdwithit 3y agoOr for a less out-there example, Ken Thompson's classic "Reflections on Trusting Trust". At some point unless you are literally producing all of the hardware and software yourself you have to trust someone. The challenge is figuring out where that line of acceptable risk lies for you. It's going to be very different for an indie game dev vs a FinTech company vs the US DoD.
- otabdeveloper4 3y agoLike the other person said, Nix solves that problem. You are in control of the entire supply chain with Nix.
- oddmiral 3y agoIf you have sources, you have full control, using any distribution method. Some Nix packages are without sources, so this is not true for Nix.
- otabdeveloper4 3y agoSupply chain management isn't about sources per se (though source makes it easier). What you need is hashes and signatures for every dependency at every step.
- oddmiral 3y agoIf you have sources, you can do anything you want at every step. If you haven't, then you can do fewer things at some steps. Some Nix packages have no sources, so full control is not available for them.
- skipnup 3y agoBut that could be said about each an any dependency. And some (very rare) companies do enforce that, everyone else has to build up a bit of trust.