this post was submitted on 29 Mar 2024
672 points (99.0% liked)
Technology
76311 readers
2882 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Have those audits you allude to ever caught anything before it went live? Cuz this backdoor has been around for a month and RedHat is affected, too. Plus this was the single owner of a package who is implicitly trusted, it's not like it was a random contributor whose PRs would get reviewed.
The code being open source helps people track it down once they try to debug an issue (performance issue and crashes because in their setup the memory layout was not what the backdoor was expecting), that's true. But what actually triggered the investigation was the bug. After that it's just a matter of time to trace it back to the backdoor. You understimate reverse engineers. Or maybe I'm just spoiled.
How long until US bans code from developers with ties to CN/RU?
That won't happen because it would effectively mean banning all FOS which isn't remotely practical.
How do you propose we meaningfully fix this issue? Hoping random people catch stuff doesn't count.
An open source project that does nothing but security audits on other open source projects?
https://github.com/google/oss-fuzz/pull/10667#pullrequestreview-1518981986
This person says OSS Fuzz would not have found it.
How do you interpret the reactions to that comment that you linked?
I ask in trying to understand how to interpret the comment accuracy/validity.
That's a great question. No way to tell. It's freaking emoji.
A thumbs down could be displeasure of the product not being able to catch it, or it could be them not liking the comment because they think it's untrue.
A fuzzer might catch the crashes related to the memory layout? But its purpose is to look for vulns not malice.
The dude himself is legit tho, he probably owns OSS Fuzz
https://www.linkedin.com/in/jonathan-metzman-b8892688
https://security.googleblog.com/2021/03/fuzzing-java-in-oss-fuzz.html
So many different ones too, not just up or down thumb emojis.
In time it may become a trade-off between new (with associated features and speed) Vs tried and tested/secure.
To us now this sounds perverse, but remember that NASA generally use very old hardware because they can be more certain the various bugs & features have been found and documented. In NASA's case this is for reliability. I'll concede 'brute force' does add another dimension when applying this logic to security.
This may also become an AI arms race. Finding exploits is likely something AI could become very good at - but a better AI seeking to obfuscate?