4 ms·
>Also, open-source is of course safer and some of us have been repeating for years that you can't trust binary blobs, security being just one reason out of many
by cube13 13y ago
>Also, open-source is of course safer and some of us have been repeating for years that you can't trust binary blobs, security being just one reason out of many.
Only if you're auditing the code and building it yourself, or have a trusted place where that's done. I would wager that for the vast majority of users are just using the binary blob provided by someone. Otherwise, the "code" you're using could be as compromised as any closed source program.
- dllthomas 13y agoNo, the fact that others can compare things means there's still some improvement in security. Even if it's not actually done, there's a greater threat of it being done, so it's a less tempting target. To be sure, absent the measures you describe the effect is significantly weaker than with them, and other effects may dominate.
- cube13 13y agoAre you positive that the binary blob of the open source project you just downloaded is 100% from the code in it's repo? If you're not, then it absolutely is not an improvement. The attack vector has just shifted slightly.
- dllthomas 13y agoYes, because nothing can ever improve security unless it is 100%. Using FLOSS, alone, is a marginal improvement in security, other things being equal. It can be combined with still other measures to make a bigger difference.
- bad_user 13y agoAgain with the vast majority of users fallacy? Bring up a story of grandma for a full picture too. Binary blobs can be checked easily if they originated from the source code published. Major Linux distributions, like Debian, have people all over the world auditing the repository. If a backdoor is planted, with the repository being public, most projects have a full history of whom added what and when. Code reviews happen too.
- deleted 13y ago[deleted]
- derefr 13y agoYou're right in that this mostly foils the NSA in its role as a global passive attacker. However, having a FOSS OS doesn't foil active, targeted attacks at all: the version of a package in the repo could be perfectly safe, while the version distributed to just your computer could be backdoored. (The NSA, after all, can FISA-order someone to give up their package signing key just as well as they can grab a decryption key, and then MITM just your connection to deliver an "automatic security update" that nobody else got.)
- consonants 13y agoFBI did just this and pushed a special update to bug a member of a mob's dumbphone a relatively long time ago.
- tedunangst 13y agoI love how this story keeps getting better with time.
- nitrogen 13y ago...while the version distributed to just your computer* could be backdoored.* They would have to get the base distribution signing key, which is probably a shared secret that requires multiple people to unlock. Have there been any hints of NSLs or FISC orders requiring the disclosure of private Linux distribution keys, some of which may not even be held in the US?
- derefr 13y agoThe funny thing is, you don't actually need to replace a package that's part of the base distribution. Every package format we have (RPM, DEB, etc.) runs its install- and upgrade-scripts as root, so every package can potentially do anything on install, including patching the installed files of other packages (or cleverer things, like adding SSL trust roots.) So, since they don't specifically need to patch your openssl package to compromise your openssl library, they could just as well suborn the signing key of (presuming Ubuntu) some PPA author, as long as the user they're trying to bug has that PPA in their sources.list.
- bigiain 13y agoAnd you're auditing the compiler code, which you bootstrapped up yourself without using a possibly backdoored compiler on the way. (I wonder if anyone's audited gcc/clang binaries installed in readily available linux/bsd/MacOSX distros to see if they're free of "Reflections on Trusting Trust" concerns?)
- dllthomas 13y agoI don't know the answer to your question, but it's worth noting that "auditing the binaries" no longer has to mean looking through every line of disassembled byte-code, as was originally thought: http://www.dwheeler.com/trusting-trust http://www.dwheeler.com/trusting-trust