6 ms·
That's really just a question of trust. If you know what Composer is, you trust it. 'apt-get install whatever' is just as magically scary and dangerous.
by timaelliott 14y ago
That's really just a question of trust. If you know what Composer is, you trust it.
'apt-get install whatever' is just as magically scary and dangerous.
- Kudos 14y agoNo it isn't, there's GPG signing and things going on there.
- Udo 14y agoNo it isn't, there's GPG signing and things going on there. That's really just Cargo Cult security, isn't it? Signed packages can just as easily be malicious. In fact a repository server could be a much worthier target for the injection of bad code than a single, relatively obscure web project.
- Dylan16807 14y agoThe difference is the same as between http and https.
- Udo 14y agoExactly. SSL doesn't guarantee that the content is benign either. But there is also a key difference when it comes to software distribution. On a typical web connection you worry about 3rd parties observing your content and maybe even spoofing it later (e.g. stealing your cookies), but as far as downloads are concerned your main worry is actually content integrity. This integrity is threatened by both malicious publishers and outside attackers injecting malicious code into otherwise benign software - having a GPG signature alongside your rpm does (almost) nothing to mitigate that risk.
- jasonlotito 14y agoNot sure if you are trying to make a joke (and if so, it's incredibly subtle), or you are being serious. In case you are serious, to explain how HTTPS as it's used means anything about the trust-worthiness of the two parties involved?
- Dylan16807 14y agoLook at the original post. "curl -s http://getcomposer.org/installer http://getcomposer.org/installer | php" It's not just about trusting Composer, it's about trusting every point between you and their server. If I want to know that I am actually executing Composer I need to use a secure download method.
- eli 14y agoI don't disagree with you, but if you've got someone actively trying to exploit you sitting between you and the Internet, you've got bigger problems.
- simonbrown 14y agoSomeone trying to find an exploit is a bigger problem than giving them one?
- eli 14y agoOh, definitely. If someone has a launched a targeted attack against you and they already have the ability to seamlessly view and modify your internet traffic, you are in pretty serious trouble whether you download your development tools from wget or apt-get.
- anthonyb 14y agoExcept that apt-get will check GPG signatures and detect that kind of attack. How is a MITM attack going to find a 3rd party's private key?
- anthonyb 14y agoIt does not help you if the originating server has been hacked, which is by far the most likely attack vector (after people being assholes on the internet or making mistakes in their script). Protecting against that is the whole fucking point of using things like apt-get/PEAR and GPG/code signing.
- anthonyb 14y agoThe repository doesn't have any access to the developer's private key. That's exactly the attack that they're designed to mitigate.
- brohee 14y agoSigned packages can be just as malicious, but the security of the mechanism relies on the signer not wanting to do jail time, thus protecting his secrets and not signing stuff he doesn't trust.