Re: Reflections on Trusting Trust

看板FB_security作者時間20年前 (2005/11/30 16:58), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串19/36 (看更多)
On Sze, November 30, 2005 12:43 am, Colin Percival mondta: > Even before you get to that point, you have to worry about making sure > that the build clients are secure. One possibility which worries me a > great deal is that a trojan in the build code for a low-profile port > (e.g., misc/my-port-which-nobody-else-uses) could allow an attacker to > gain control of a build client (and then insert trojans into packages > which are built there). Which practically begs the question: could we, pretty please, change the defaults and stop encouraging people from downloading distfiles and compiling them when using the ports tree as *root*? (shudder) There is exactly zero reason for this that I can think of apart from some "well it's more convenient that way" arguments. With the current model of using ports (and packages too) every single BO or whatever in eg fetch or libfetch becomes a sure-fire remote root vulnerability, because all FreeBSD machines use fetch to retrieve stuff from random sites on the Internet (MASTERSITEs are all over the place) as root. A security worst-practice. (Well, not all of them... I use a non-priviledged user to do that, which is now becoming more and more practical, but earlier there used to be all kinds of nasties in the build processes of certain ports which you only noticed if you were non-root...) (Of course, we could go even further and start compartmentalising access rights because eg a user with port-install rights should have no permission to touch the base system, in partcular system binaries and the contents of /etc, but this would also require saying farewell to some really bizarre things like "openssh from ports overwriting the one in the base" which would be really a good idea btw.) Best regards, Sz. ----------------------------------------------------- 1 GByte ingyenes e-mail 廥 webt嫫hely a MailPont-t鏊! Mi廨t fizetn幨 廨te, ha n嫮unk teljesen ingyen van? Regisztr嫮j te is magadnak! - www.MailPont.hu - _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #13ZMc-00 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #13ZMc-00 (FB_security)