, SecurityFocus 2002-06-03
The popular open-source security tool Fragroute is bugged in plain sight by unknown hackers, who may have struck before.
Expand all |
Post comment
Download Sites Hacked, Source Code Backdoored
2002-06-04
Coldman (6 replies)
Coldman (6 replies)
Download Sites Hacked, Source Code Backdoored
2002-06-04
cras (1 replies)
cras (1 replies)
Download Sites Hacked, Source Code Backdoored
2002-06-05
Anonymous (1 replies)
Anonymous (1 replies)
Download Sites Hacked, Source Code Backdoored
2002-06-07
Chris Berry <compjma (at) hotmail (dot) com [email concealed]> (1 replies)
Chris Berry <compjma (at) hotmail (dot) com [email concealed]> (1 replies)

The argument for open source software being more secure than closed source software has nothing to do with this problem. That argument is about most visibility into the source code. Tell me, if Dug Song had distributed all his programs in binary only form, would we be any more protected from the monkey.org servers being compromised? No, in fact a virus in a binary only distribution would likely be even worse.
>Most users who download sources and then compile those >usualy don't have enough knowledge and experience to make >any changes (even small ones), so they obviously can't check >that the code is free from backdoors...
I agree with this point from a fundamental level. However, while the average user might not have the knowledge to check, there are some of us that do, or at least have our boxes locked down tight enough that we'd notice an issue like this.
Those are the ones that will get the word out.
>And concerning digital signatures... Well, again - most >users are not going to check those anyway, so... It is >possible to force signature checking on binary installation >in some systems, but you just cannot force this in case of >sources. No way...
Agreed..sort of. ;) I admit, I don't have a good solution for this problem, digital signatures do help, just not enough.
--Dox
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/462/12888#12888