4 ms·
Where do you think they got the package from?
by theboss 13y ago
Where do you think they got the package from?
- eikenberry 13y agoCompiled from source.
- IgorPartola 13y agoTo be fair, not where you think he got it from (it seems). For example, in Ubuntu you download all packages over plain HTTP. Worried yet? Don't be. Let me tell you why: A Debian repository (a repository of .deb packages) is a directory containing *.deb files, a list of packages in a file called Packages and a description of the repository in a file called Release. Every package listed in Packages includes the filename, the name and version of the package, and several checksums of the file (typically MD5sum, SHA1, SHA256, and SHA512). Thus if you trust Packages you can verify the integrity of the .deb file. Why should you trust the Packages file? Well, it's checksums are listed in the Release file. Why should you trust the Release file? Because there is a signature of it available in Release.gpg file. The signature is created by the distribution maintainers. How can you trust this signature? Because your initial installation ISO, etc. came with the public key of the distribution maintainers which APT uses to verify all the packages. How can you trust the ISO you used to install it? Because presumably you verified the checksums of it when you downloaded it, and you obtained those checksums over a secure channel at the time of the installation.
- theboss 13y agoI'm aware how you download packages but I don't know how Ubuntu actually gets the packages it will be distributing. How do we know Ubuntu isn't distributing a trojan'ed version of keepass?, is what I'm saying. If keepass doesn't have a secure mechanism for distribution then how can you be sure Ubuntu got the correct copy?
- IgorPartola 13y agoIf I was an attacker able to get packages in Ubuntu compromised I wouldn't be going after KeePass. I would go after a browser, a random utility normally run by root, or the kernel itself. If Ubuntu is giving you poisoned packages, you are hosed. Game over, no security. You "know" that Ubuntu is not distributing rogue packages because the author of the package and the Debian package maintainer are different people. Presumably the Debian package maintainer peer-reviews the code they are including in the distro for security issues, and puts their name and reputation on the line (hence the Debian maintainers' signatures on the distro itself). What you are really asking is "how can I trust code written by other people". You cannot. If you are taking the paranoia to this level, then don't use computers at all. We do not have a system in place for not trusting the OS, or the hardware. You must put a line in the sand somewhere and say "I trust these people". Otherwise, you cannot even trust your `cat` command to review the source code of the software you want to trust, and you'd have to spend more than your lifetime reviewing every bit of code you are currently using to read HN in order to know for sure that it's secure (assuming you are able to spot all malicious, or just insecure code).
- sigterm 13y ago> What you are really asking is "how can I trust code written by other people". You cannot. That's not his point. The concern is that without a secure channel of distribution from the author, Ubuntu can be MITM'ed into packaging a tampered binary.
- IgorPartola 13y agoUbuntu absolutely can be MITM'ed. So can you when downloading the source code. Moreover, you don't have to MITM attack Ubuntu (or rather Debian) into downloading a compromised version of the KeePass source. You could MITM attack anything the Ubuntu/Debian developers download, whether it be the source code to stuff that's going into Debian/Ubuntu as a package or something they are installing on their machines. I repeat, at some point you have to trust someone, otherwise all software and hardware is suspect. Now, the really big question to ask here is what processes do we have in place for this not to happen. Downloading stuff over HTTPS is clearly not good enough: there are many ways someone willing to compromise a distro can circumvent it (including forcing a CA to give out a rouge certificate, or simply threatening the individual software developer into accepting a malicious patch). The best I can think of is using the PGP/GPG web of trust. When Debian Maintainer Dave gets an updated version of the source for package foo from Programmer Pete, Dave can verify that Pete actually authored the code by making sure the source is properly signed with Pete's GPG key. Dave knows Pete's public key having properly exchanged keys with him in person. I think that's the best we can do. Mind you in the above we cannot guarantee that Pete does not turn to the dark side, either willingly or forced into it by a powerful adversary (NSA, drug cartels, etc.) The best we can do is that Dave is not also turned to the dark side and that Dave carefully reads and catches any security issues with the code Pete delivers to him. This is what keeps your distro safe, nothing else, so buy a maintainer a beer next time you meet one.
- bad_user 13y agoDistributions like Ubuntu are not picking up and distributing random packages from the Internet. Usually it's either the software author that does the packaging by himself, or a package maintainer that has a direct relationship with the software author. Encryption/signing is only for proving that the source is who it claims it is. It doesn't mean that you can trust the software itself. Towards that end you've got source-code. Ubuntu's software packages are built from source and you can inspect it - yes it may not be feasible, leaks may escape even trained eyes and so on and so forth, but the source-code is there available for inspection and nothing short of a source-code review can prove that the software does what it claims.
- IgorPartola 13y agoThat is assuming you can trust your tools, OS, and hardware to show you the real source code :). How do you know that your editor or your compiler are not messing with you? But yes, you are correct. BTW, in the case of Debian, software authors are discouraged to package the software themselves and instead are encouraged to work with maintainers instead. I see this as a net win as there is at lest one more pair of eyes on the software before it ends up on my machines.
- theboss 13y agoThe only point I'm making, and I hope the other guy reads this as well, is that keepass isn't as bullet proof as people act it is when criticizing last pass. It has its problems, just like last pass. I was simply playing devil's advocate. It's very much the "Oh I don't get viruses I have a Mac" argument that I've heard a lot of non-computer people say. This is undeniable because I'm sure many windows keepass users go to the site every download.
- IgorPartola 13y agoOK. I guess for me it sounded like you were saying the big problem is with the actual download of the software, not with the software itself. That's two different beasts that need to be attacked very differently.
- bad_user 13y agoDistributions are signing distributed packages with trusted keys by PGP. PGP signing is a fairly standard mechanism by which somebody can prove that he packaged that software. The interesting bit is ... if a web of trust can be established, this is far, far more secure than distributing binaries by HTTPS. That's because the private keys with which those packages get signed DO NOT have to be distributed or installed on any public servers on this internet and thus this mechanism is invulnerable to exploits such as Heartbleed. And in the case of Linux distributions, this web of trust can easily be established, because the package maintainers and software authors know each other. In the right context, the web of trust model can be much more secure than SSL/TLS, because SSL/TLS requires X.509 certificates that have to be issued by a central authority - and we'll always have problems with central authorities that go rogue or have their root keys stolen. And you can't rely on the central authority model if you want protection against the NSA. Too bad that PGP signing/encryption isn't too popular, since the web of trust model only works if there are enough people vetting for each other. But for Linux distributions it works just fine ;-) Here, read more about it: https://en.wikipedia.org/wiki/Pretty_Good_Privacy https://en.wikipedia.org/wiki/Pretty_Good_Privacy
- IgorPartola 13y agoMoreover, unlike HTTPS/X.509 you don't have a problem where another CA can just issue a certificate in your name. That is, if you hold a private key for a cert for .example.com from VeriSign, Comodo can issue someone else a valid certificate for .example.com and your users would not know the difference. With PGP/GPG there is no CA: you create a private/public key pair and initially nobody trusts it. But by exchanging and signing keys through the extremely laborious process of verifying identities you actually establish trust for your specific key, thus making this system much more robust.