4 ms·
Do you also trust your package maintainer to not mismerge patches and leave you open to security bugs? Your argument is no bueno.
by flebron 11y ago
Do you also trust your package maintainer to not mismerge patches and leave you open to security bugs? Your argument is no bueno.
- kekebo 11y agoThis whole issue got raised by the package maintainers from debian[1], so yeah, there are sources and people you could consider to trust. But of course nothing beats compiling from source. [1]https://news.ycombinator.com/item?id=9724409 https://news.ycombinator.com/item?id=9724409
- cwyers 11y agoIf you don't have the time, skillset or inclination to review the source you're compiling yourself, trusting a third party who you have reason to put faith in beats compiling from source yourself.
- dtech 11y ago> But of course nothing beats compiling from source. Did you assemble a bootstrap compiler yourself? Your binary compiler could be backdoored! [1] [1] https://en.wikipedia.org/wiki/Backdoor_(computing)#Compiler_backdoors https://en.wikipedia.org/wiki/Backdoor_(computing)#Compiler_...
- hahainternet 11y agoI've no idea why you've been downvoted. While it's not amazingly pertinent, it's worthy to note that security from source assumes your compiler is being honest.
- kbenson 11y agoYou have to extend trust out at some point. Your only other alternative is to manually type the machine code required for a C compiler and start from that. Additionally, it's fairly ironic this is about a browser. If you don't trust packages maintainers, yet you want to use a browser, which the whole point of is to download and interpret text, code and binaries which you have little in the way of actually controlling after pointing it at a site, then I think you've made some interesting security trade-offs in your mind.
- feld 11y agoIt's easier to trust that the maintainer compiled upstream properly instead of backported/mismerged because of a stupid OS policy preventing you from incrementing version numbers
- ackalker 11y agoErgo: use a distribution like Arch Linux or Gentoo. Arch Linux has the advantage that you don't have to build everything from source yourself. Both have the advantage that the build scripts are easy to understand (Arch PKGBUILDs more so, IMHO). In the end you will always arrive at a chicken and egg situation, you will ultimately need to trust the engineers who designed your CPU and chipset, the VLSI design software which they used, the developers who wrote the compiler and toolchain, the tools used to bootstrap it, external libraries, etc. The world ultimately runs on trust, no matter how you slice it.
- runjake 11y agoAnd even then, who knows? http://wccftech.com/intel-possibly-amd-chips-permanent-backdoors-planted-nsa-updated-1/ http://wccftech.com/intel-possibly-amd-chips-permanent-backd...
- kbenson 11y agoOkay, so the only other alternative is to create your own processor[1], manually type the machine code required for a C compiler, and then start from that. Sheesh. Really, this is what everything in life is like. Every time you cross a bridge, you are implicitly trusting the builders who built it, the engineers who designed it, the mechanical engineering processes they used, and the mathematical disciplines that they rely on, all the way down to their fundamental axioms. You have to extend trust at some point there as well, otherwise you can start by proving there exists a class of numbers we will call integers... 1: https://news.ycombinator.com/item?id=9755742 https://news.ycombinator.com/item?id=9755742
- runjake 11y ago