Re: Next steps from GTI TAC meeting on 2023-03-08 - Evaluate cost of glibc migration.
Brian Behlendorf <[email protected]> Wed, 24 May 2023 11:55:11 -0700
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Message-ID | <[email protected]> |
On 5/24/23 11:13, Siddhesh Poyarekar wrote: > On 2023-05-24 12:29, Konstantin Ryabitsev wrote: >> [...] >> GCC and other projects are sufficiently high targets that we should >> not trust >> the infrastructure to be secure or admins to be above being bribed or >> forced >> under duress. > > It looks like the question of who to ultimately trust, either the > gatekeeper committer (or two) who is the only person to have write > access to the repository, or the admin who manages the box. The > gatekeeper committer could also fabricate commits and push to the > central repository in the same way. In fact, the gatekeeper committer > could choose to do worse, like delaying (or declining to merge) > someones patches. It doesn't seem like an equal comparison - it seems like down one path there is an audit trail by which regular (machine+human) processes can detect malfeasance, while down another path there's a greater opportunity for compromise that can't otherwise be easily checked. If GNU Toolchain devs haven't developed a full threat model (that would include things like "gatekeeper delaying someone's patches") that would be nice, so that you can weigh approaches that solve some threats but not others, or a combination that maximizes coverage. Social attacks matter - from a security POV it's less "gatekeeper being lazy/a jerk" and more "gatekeeper being compromised by an attacker". > Signed commits would be nice, but we're not there yet as a community. It's not quite as easy as "hey just add -s to your git commands" but it's not far from that. I'm not a part of the TAC so I won't go further than to suggest that a migration, where there will no doubt have to be some adjustments to process and flow, to introduce other non-zero-effort but non-blocking changes that enhance overall security/integrity. Brian -- Brian Behlendorf CTO, Open Source Security Foundation [email protected] Twitter: @brianbehlendorf