3 ms·
I don't know the exact plan since I'm not working on this, but it would be relatively easy for us to do: 1. Insist that the exact build configurations used by
by briansmith 13y ago
I don't know the exact plan since I'm not working on this, but it would be relatively easy for us to do:
1. Insist that the exact build configurations used by Cisco be open-sourced along with the rest of the code.
2. Require that every binary distributed by Cisco by tagged with the revision control revision ID.
3. Internally at Mozilla, build that revision of the code and compare the result to the binary blob that we would download from Cisco. Note we'd never distribute the outputs of our internal builds; we'd use those builds only to verify that the source code matches what we'd download.
4a: When we verify that the outputs match exactly, update some embedded hashes within Firefox to approve those versions of the binary blob for download/install, or
4b: Cisco could ask Mozilla to sign these blobs for them, and Mozilla would sign the blobs after doing the above checks. Then, the Firefox client would just verify that the blobs were signed by Mozilla's public key.
- ghoul2 13y agoActually, on second thoughts - yes, you are right. This could work - partially. But the other way around. Mozilla could build the blobs, sign them and then send them to Cisco who would then provide the download infrastructure. It still won't allow a third party to verify the same and would require everyone to trust Mozilla itself. Its less problematic than having to trust Cisco, but far from ideal. On that note: do you know if the blob download would be wrapped in a Cisco EULA?
- BrendanEich 13y agoWe can't build blobs without taking the MPEG LA license. Blobs can be verified against the open source. See https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binaries-analysis/ https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie.... More on this in a future blog post. /be