oss-sec mailing list archives
Re: Mitigating malicious packages in gnu/linux
From: Ludovic Courtès <ludo () gnu org>
Date: Tue, 19 Nov 2019 17:00:00 +0100
Hi, Tim Kuijsten <info+oss-security () netsend nl> skribis:
There is not a definitive solution here. But there are multiple efforts and research going on. The most important one, in my opinion, is the reproducible builds project [1]. We need to ensure we are not inserting random or non-deterministic data into our build artifacts. This stretches from upstream developers providing tarballs, to pre-compiled sources and packages from distributions. There is no distribution today that has full reproducible builds, but there are many projects that work towards this and work on reproducible builds.One attack that is not solved by reproducible builds is one on the toolchain. This can be solved with bootstrappable builds[1] which is about minimizing the number of trusted binaries that are needed to produce the toolchain, that produced the toolchain, ... that was used to build your package.
Efforts in that area are fruitful and have already led to a smaller set of “bootstrap seeds” (binaries from which the rest of the system is built from source) for GNU Guix, an important step forward: https://guix.gnu.org/blog/2019/guix-reduces-bootstrap-seed-by-50/ Thanks to people working on GNU Mes and related projects at <https://bootstrappable.org/>, we have good hope to see that set of bootstrap seeds further reduced soon. Reproducible builds and bootstrappable builds enable provenance tracking and auditing, which are key to security. Ludo’.
Current thread:
- Mitigating malicious packages in gnu/linux Georgi Guninski (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Morten Linderud (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Stuart D. Gathman (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Tim Kuijsten (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Ludovic Courtès (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Morten Linderud (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Pavel Heimlich (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Jakub Wilk (Nov 19)
- Re: Mitigating malicious packages in gnu/linux Solar Designer (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Russ Allbery (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Solar Designer (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Mark Hatle (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Russ Allbery (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Aditya Sirish Arunkumar Yelgundhalli (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Bob Friesenhahn (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Jeremy Stanley (Nov 20)
- Re: Mitigating malicious packages in gnu/linux Morten Linderud (Nov 19)