4 ms·
I'm aware how you download packages but I don't know how Ubuntu actually gets the packages it will be distributing. How do we know Ubuntu isn't distributing a
by theboss 13y ago
I'm aware how you download packages but I don't know how Ubuntu actually gets the packages it will be distributing.
How do we know Ubuntu isn't distributing a trojan'ed version of keepass?, is what I'm saying. If keepass doesn't have a secure mechanism for distribution then how can you be sure Ubuntu got the correct copy?
- IgorPartola 13y agoIf I was an attacker able to get packages in Ubuntu compromised I wouldn't be going after KeePass. I would go after a browser, a random utility normally run by root, or the kernel itself. If Ubuntu is giving you poisoned packages, you are hosed. Game over, no security. You "know" that Ubuntu is not distributing rogue packages because the author of the package and the Debian package maintainer are different people. Presumably the Debian package maintainer peer-reviews the code they are including in the distro for security issues, and puts their name and reputation on the line (hence the Debian maintainers' signatures on the distro itself). What you are really asking is "how can I trust code written by other people". You cannot. If you are taking the paranoia to this level, then don't use computers at all. We do not have a system in place for not trusting the OS, or the hardware. You must put a line in the sand somewhere and say "I trust these people". Otherwise, you cannot even trust your `cat` command to review the source code of the software you want to trust, and you'd have to spend more than your lifetime reviewing every bit of code you are currently using to read HN in order to know for sure that it's secure (assuming you are able to spot all malicious, or just insecure code).
- sigterm 13y ago> What you are really asking is "how can I trust code written by other people". You cannot. That's not his point. The concern is that without a secure channel of distribution from the author, Ubuntu can be MITM'ed into packaging a tampered binary.
- IgorPartola 13y agoUbuntu absolutely can be MITM'ed. So can you when downloading the source code. Moreover, you don't have to MITM attack Ubuntu (or rather Debian) into downloading a compromised version of the KeePass source. You could MITM attack anything the Ubuntu/Debian developers download, whether it be the source code to stuff that's going into Debian/Ubuntu as a package or something they are installing on their machines. I repeat, at some point you have to trust someone, otherwise all software and hardware is suspect. Now, the really big question to ask here is what processes do we have in place for this not to happen. Downloading stuff over HTTPS is clearly not good enough: there are many ways someone willing to compromise a distro can circumvent it (including forcing a CA to give out a rouge certificate, or simply threatening the individual software developer into accepting a malicious patch). The best I can think of is using the PGP/GPG web of trust. When Debian Maintainer Dave gets an updated version of the source for package foo from Programmer Pete, Dave can verify that Pete actually authored the code by making sure the source is properly signed with Pete's GPG key. Dave knows Pete's public key having properly exchanged keys with him in person. I think that's the best we can do. Mind you in the above we cannot guarantee that Pete does not turn to the dark side, either willingly or forced into it by a powerful adversary (NSA, drug cartels, etc.) The best we can do is that Dave is not also turned to the dark side and that Dave carefully reads and catches any security issues with the code Pete delivers to him. This is what keeps your distro safe, nothing else, so buy a maintainer a beer next time you meet one.
- bad_user 13y agoDistributions like Ubuntu are not picking up and distributing random packages from the Internet. Usually it's either the software author that does the packaging by himself, or a package maintainer that has a direct relationship with the software author. Encryption/signing is only for proving that the source is who it claims it is. It doesn't mean that you can trust the software itself. Towards that end you've got source-code. Ubuntu's software packages are built from source and you can inspect it - yes it may not be feasible, leaks may escape even trained eyes and so on and so forth, but the source-code is there available for inspection and nothing short of a source-code review can prove that the software does what it claims.
- IgorPartola 13y agoThat is assuming you can trust your tools, OS, and hardware to show you the real source code :). How do you know that your editor or your compiler are not messing with you? But yes, you are correct. BTW, in the case of Debian, software authors are discouraged to package the software themselves and instead are encouraged to work with maintainers instead. I see this as a net win as there is at lest one more pair of eyes on the software before it ends up on my machines.
- theboss 13y agoThe only point I'm making, and I hope the other guy reads this as well, is that keepass isn't as bullet proof as people act it is when criticizing last pass. It has its problems, just like last pass. I was simply playing devil's advocate. It's very much the "Oh I don't get viruses I have a Mac" argument that I've heard a lot of non-computer people say. This is undeniable because I'm sure many windows keepass users go to the site every download.
- IgorPartola 13y agoOK. I guess for me it sounded like you were saying the big problem is with the actual download of the software, not with the software itself. That's two different beasts that need to be attacked very differently.