Re: My suggestions on auditing that services are running free software
Carlos O'Donell <[email protected]> Wed, 3 Apr 2024 14:55:09 -0400
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
On 3/22/24 11:57, Konstantin Ryabitsev wrote: > On Fri, Mar 22, 2024 at 04:35:13AM -0400, Ian Kelling wrote: >> I suggest that CTI come up with a proposal/plan for how to implement the >> audit. Eg, checking what software is being run and that users are able >> to download a copy and that it is free software. The FSF will be >> available to review the proposal. > > Before we go down that route, please note that LF IT does not provide backend > access to third parties, so any audit plans will be limited to auditing > documentation. I agree, and I would not want any service provider to give backend access to third parties because it creates an increased security risk to support the audit. The cost of compliance is relevant here if it creates a security risk. We can achieve compliance without the additional risk. For me as a CTI TAC member is reasonable to have a documented list of the versions of the software that was being run, audit the list, and update the list with versions on the CTI website. > We, of course, comply with licensing terms, so any AGPL-licensed software > (such as public-inbox) is available for download (we run the upstream version > without any modifications). Any free software without such requirement may > have basic version info, not necessarily down to the exact patch level. For > example, I doubt anyone benefits from knowing the exact version of Postfix > used to send this mailing list message. The purpose of the audit is to ensure that we meet the ethical repository hosting criteria and we can meet those obligations by ensuring we run unpacked distro versions or unpatched upstream versions of the software. Where we deviate from upstream or distro versions we should do so only briefly to address security issues. Knowing the exact version of Postfix is *less* important to me than knowing that we are running without any local patches applied and using the standard distro version or standard upstream release. So it would be a checkbox item for me to ask "Are we using the distro version? Are we using upstream directly?" Does that make sense? -- Cheers, Carlos.