Re: Next steps from GTI TAC meeting on 2023-03-08 - Evaluate cost of glibc migration.

Brian Behlendorf <[email protected]> Wed, 24 May 2023 11:55:11 -0700
Newsgroups org.linuxfoundation.lists.cti-tac
Message-ID <[email protected]>
On 5/24/23 11:13, Siddhesh Poyarekar wrote:
> On 2023-05-24 12:29, Konstantin Ryabitsev wrote:
>> [...]
>> GCC and other projects are sufficiently high targets that we should 
>> not trust
>> the infrastructure to be secure or admins to be above being bribed or 
>> forced
>> under duress.
>
> It looks like the question of who to ultimately trust, either the 
> gatekeeper committer (or two) who is the only person to have write 
> access to the repository, or the admin who manages the box.  The 
> gatekeeper committer could also fabricate commits and push to the 
> central repository in the same way.  In fact, the gatekeeper committer 
> could choose to do worse, like delaying (or declining to merge) 
> someones patches.

It doesn't seem like an equal comparison - it seems like down one path 
there is an audit trail by which regular (machine+human) processes can 
detect malfeasance, while down another path there's a greater 
opportunity for compromise that can't otherwise be easily checked.

If GNU Toolchain devs haven't developed a full threat model (that would 
include things like "gatekeeper delaying someone's patches") that would 
be nice, so that you can weigh approaches that solve some threats but 
not others, or a combination that maximizes coverage. Social attacks 
matter - from a security POV it's less "gatekeeper being lazy/a jerk" 
and more "gatekeeper being compromised by an attacker".

> Signed commits would be nice, but we're not there yet as a community.

It's not quite as easy as "hey just add -s to your git commands" but 
it's not far from that. I'm not a part of the TAC so I won't go further 
than to suggest that a migration, where there will no doubt have to be 
some adjustments to process and flow, to introduce other non-zero-effort 
but non-blocking changes that enhance overall security/integrity.

Brian

-- 
Brian Behlendorf
CTO, Open Source Security Foundation
[email protected]
Twitter: @brianbehlendorf