5 ms·
As a user of fedora what does this actually get me? I mean I understand it for hermetic builds but why?
by nimish 1y ago
As a user of fedora what does this actually get me? I mean I understand it for hermetic builds but why?
- deleted 1y ago[deleted]
- jacobgkau 1y agoMy impression is that reproducible builds improve your security by helping make it more obvious that packages haven't been tampered with in late stages of the build system. * Edit, it's quoted in the linked article: > Jędrzejewski-Szmek said that one of the benefits of reproducible builds was to help detect and mitigate any kind of supply-chain attack on Fedora's builders and allow others to perform independent verification that the package sources match the binaries that are delivered by Fedora.
- Zamicol 1y agoBingo.
- deleted 1y ago[deleted]
- kazinator 1y agoThe supply chain attacks you have to most worry about are not someone breaking into Fedora build machines. It's the attacks on the upstream packages themselves. Reproducible builds would absolutely not catch a situation like the XZ package being compromised a year ago, due to the project merging a contribution from a malicious actor. A downstream package system or OS distro will just take that malicious update and spin it into a beautifully reproducing build.
- yjftsjthsd-h 1y agoDon't let the perfect be the enemy of the good; this doesn't prevent upstream problems but it removes one place for compromises to happen.
- deleted 1y ago[deleted]
- kazinator 1y agoI'm not saying don't have reproducible builds; it's just that this is an unimportant justification for them, almost unnecessary. Reproducible builds are such an overhelmingly good and obvious thing, that build farm security is just a footnote.
- drewcoo 1y agoYour mere footnote is my soft, soft underbelly. Any hardening is still hardening.
- phkahler 1y agoAnd anything designed to catch upstream problems like the XZ compromise will not detect a compromise in the Fedora package build environment. Kinda need both.
- bluGill 1y agoReproducible builds COULD fix the xz issues. The current level would not, but github could do things to make creating the downloadable packages scrip table and thus reproducible. Fedora could checkout the git hash instead of downloading the provided tarball and again get reproducible builds that bypass this. The above are things worth looking at doing. However I'm not sure what you can code that tries to obscure the issues while looking good.
- pxc 1y agoWhen builds are reproducible, one thing a distro can do is have multiple build farms with completely different operators, so there's no shared access and no shared secrets. Then the results of builds of each package on each farm can be compared, and if they differ, you can suspect tampering. So it could help you detect tampering earlier, and maybe even prevent it from propagating depending on what else is done.
- bagels 1y agoIt's one tool of many that can be used to prevent malicious software from sneaking in to the supply chain.
- russfink 1y agoKeep in mind that compilers can be backdoored to install malicious code. Bitwise/signature equivalency does not imply malware-free software.
- bluGill 1y agoTrue, but every step we add makes the others harder too. It is unlikely Ken Thompson's "trusting trust" compiler would detect modern gcc, much less successfully introduce the backdoor. Even if you start with a compromised gcc of that type there is a good chance that after a few years it would be caught when the latest gcc fails to build anymore for someone with the compromised compiler. (now add clang and people using that...) We may never reach perfection, but the more steps we make in that direction the more likely it is we reach a point where we are impossible to compromise in the real world.
- jt2190 1y agoIn this attack, the compiler is not a reproducible artifact? Or does backdooring use another technique?
- kpcyrd 1y agoTheir point is that you'd need something like https://bootstrappable.org/ https://bootstrappable.org/ (which does exist).
- kazinator 1y agoReproducible builds can improve software quality. If we believe we have a reproducible build, that's constitutes a big test case which gives us confidence in the determininism of the whole software stack. To validate that test case, we actually have to repeat the build a number of times. If we spot a difference, something is wrong. For instance, suppose that a compiler being used has a bug whereby it is relying on the value of an unitialized variable somewhere. That could show up as a difference in the code it generates. Without reproducible builds, of course there are always differences in the results of a build: we cannot use repeated builds to discover that something is wrong. (People do diffs between irreproducible builds anyway. For instance, disassemble the old and new binaries, and do a textual diff, validating that only some expected changes are present, like string literals that have embedded build dates. If you have reproducible builds, you don't have to do that kind of thing to detect a change. Reproducible builds will strengthen the toolchains and surrounding utilities. They will flush out instabilities in build systems, like parallel Makefiles with race conditions, or indeterminate orders of object files going into a link job, etc.
- uecker 1y agoI don't think it is that unlikely that build hosts or some related part of the infrastructure gets compromised.
- tomcam 1y agoI don't know this area, but it seems to me it might be a boon to security? So that you can tell if components have been tampered with?
- bobmcnamara 1y agoBingo. We caught a virus tampering with one of our code gens this way.
- dwheeler 1y agoYes! The attack on SolarWinds Orion was an attack on its build process. A verified reproducible build would have detected the subversion, because the builds would not have matched (unless the attackers managed to detect and break into all the build processes).
- conradev 1y agoBetter security! A malicious actor only needs to change a few bytes in either the source or binary of OpenSSL to break it entirely (i.e. disable certificate checking). Reproducible builds remove a single point of failure for authenticating binaries – now anyone can do it, not just the person with the private keys.