BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Good and Bad Crypto
- Subject: [Discuss] Good and Bad Crypto
- From: invalid at pizzashack.org (Derek Martin)
- Date: Tue, 22 Apr 2014 14:24:49 -0500
- In-reply-to: <1afcd60c08f54ca29e464853d8f18bb4@CO2PR04MB684.namprd04.prod.outlook.com>
- References: <14b5446b65314ece8402914040d7efb6@CO2PR04MB684.namprd04.prod.outlook.com> <5355DA7B.4070600@gmail.com> <f134eeeef944486ca75cd35da6f930e7@CO2PR04MB684.namprd04.prod.outlook.com> <20140422153609.GL3247@dragontoe.org> <1afcd60c08f54ca29e464853d8f18bb4@CO2PR04MB684.namprd04.prod.outlook.com>
On Tue, Apr 22, 2014 at 06:37:51PM +0000, Edward Ned Harvey (blu) wrote: > Supposing a bad guy writes software, open source, and makes it > available for download in source form as well as precompiled binary, > where he's compiled some trojan into the binary. Yes, this can happen. And only if the source is available to you, do you have ANY opportunity to verify it or rule it out. If there is no source, there is no possible way for you to know. > You're saying, that the only way anybody in the world can trust > anything, is to literally download everything from source, *read* > all the source, and compile it themselves. That's not what I'm saying actually, but what you have said is literally and factually a true statement. You can also choose to trust the software, based on the vendor's reputation, but this is a fantasy. You can choose to trust them also on the basis that if you are damaged you can sue them to recover your damages, there's a very good chance that this also is a fantasy. Nevertheless we must all do this to some extent, because there isn't enough time (or expertise for that matter) to thoroughly individually evaluate every piece of software we install, let alone every decision we make. But there are those who make their living by investigating the flaws in published software. Their work, by its nature, must be verifiable. Their work, by its nature, is certainly easier when they have the source code. It's almost hard to follow some news source these days without running afowl of some business or government corruption motivated by self-interest. Your lack of imagination in this regard is kind of disturbing, for someone who claims to be "pretty good at this." > I call BS. Calling BS on something doesn't make it false. -- Derek D. Martin http://www.pizzashack.org/ GPG Key ID: 0xDFBEAD02 -=-=-=-=- This message is posted from an invalid address. Replying to it will result in undeliverable mail due to spam prevention. Sorry for the inconvenience.
- Follow-Ups:
- [Discuss] Good and Bad Crypto
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Good and Bad Crypto
- References:
- [Discuss] Good and Bad Crypto
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Good and Bad Crypto
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] Good and Bad Crypto
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Good and Bad Crypto
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] Good and Bad Crypto
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Good and Bad Crypto
- Prev by Date: [Discuss] Good and Bad Crypto
- Next by Date: [Discuss] Good and Bad Crypto
- Previous by thread: [Discuss] Good and Bad Crypto
- Next by thread: [Discuss] Good and Bad Crypto
- Index(es):