Remix.run Logo
charcircuit a day ago

So much time has been wasted by the open source community on pointless projects like this.

>Reproducible builds allow people to "have more confidence that the binary you are using, which is actually executing on the computer, corresponds to the source code".

The developer signing the build provides sufficient guarantees. Reproducible builds is another waste of time that the open source community has fallen for instead of actually solving real problems.

>Bootstrappable builds can prevent the kinds of problems that Ken Thompson described in his famous Turing Award lecture: Reflections on Trusting Trust.

So much time is being spent on a theoretical problem. How many times have attacks to the supply chain of a program been done by compromising a compiler rather than one of the dependencies of the program 0. Why is time being spent on attacks which have never shown up in the wild?

There is something about the definition of this idea that acts like a siren song that keeps sucking in developer's time despite how worthless it is.

lrvick a day ago | parent | next [-]

> The developer signing the build provides sufficient guarantees.

There are tons of documented cases of people resorting to physical attacks to obtain valuable cryptographic signing keys stored in full in one place.

https://github.com/jlopp/physical-bitcoin-attacks

I can only guess the people painting targets on their backs that big are woefully unaware of it, or living in deep survivors bias.

Trusting control of the entire internet to the laptop memory holding the PGP signing key that signs debian packages of GCC was always an insane thing to do, and still is.

Imagine what happens when one of those maintainers decides they like bribes or do not like being hit with rubber hoses.

Quorum signing of full source bootstrapped deterministic builds completed on independently owned and geo-distributed hardware produced by different vendors is currently the only viable solution to greatly reduce the incentive to coerce maintainers.

charcircuit a day ago | parent [-]

Reproducible builds and bootstrapping doesn't stop physical extortion of shipping a new compromised version either.

lrvick 9 hours ago | parent [-]

Sure it does, if you deterministically full source bootstrap, build, and sign the same image m-of-n places with different hardware owned by different people, all of whom only sign if everyone gets identical results, and this can be easily verified with remote attestation at runtime on a running server.

This is not a fantasy. This is exactly how https://caution.co works.

We can cryptographically attest with high confidence what code is running on a remote server at any given moment with these tactics. Entire classes of attacks are taken off the table with this approach, including BGP attacks if deployed properly.

charcircuit 4 hours ago | parent [-]

You do not need bootstrapping or reproducibility for this. You can do the same thing just with a prebuilt OS and applications.

This is my point. Bootstrapping and reproducibility are made up problems that people think are important but are not actually needed.

moring a day ago | parent | prev | next [-]

Just for perspective, the people working on his are pursuing their hobbies and sharpening their programming skills. In contrast, you are using your time to whine about it on the internet.

charcircuit a day ago | parent [-]

People can still pursue their hobbies and sharpen their programming skills by working on more productive issues that exist. While you could call my comment whining, if it is able to change maybe even one person's opinion on the utility of this work it could help lead to a bigger reprioritization of people's time allowing for more important issues that affect real users to be addressed instead.

justivy 20 hours ago | parent [-]

>People can still pursue their hobbies and sharpen their programming skills by working on more productive issues that exist.

No, they can't. People pursue things that interest them, if it isn't interesting they wouldn't do it at all.

This is similar to "why donate to cause X when cause Y is much more important?" well if cause X didn't exist, those people likely wouldn't donate at all, so it's not really an opportunity cost.

charcircuit 20 hours ago | parent [-]

Except I'm not saying there is only X and Y. I'm saying there is AAAAA-ZZZZZ and people working on problem XYZAB would be able to help actually push these operating systems forward if they chose another problem they also found interesting. I do not believe that it is only possible for these people to be interested in a single problem. I think these people can be motivated to find another problem more interesting.

justivy 19 hours ago | parent [-]

> I think these people can be motivated to find another problem more interesting.

You can pay them I guess, usually a good motivator.

charcircuit 18 hours ago | parent [-]

That is one way, but there are other ways to motivate and demotivate people.

Rochus 20 hours ago | parent | prev | next [-]

This project is not pointless at all. It's not about "reproducible builds", but about building a full present system from "first principles". It would be a way out of a significant dependability problem barely anyone today is aware of.

charcircuit 18 hours ago | parent [-]

>way out of a significant dependability problem

This is not an actual problem. It is a made up problem that acts as honey attracting people to obsess over it.

Rochus 17 hours ago | parent [-]

Well, it might not be your actual problem. But there are always people who look a little further beyond the horizon.

charcircuit 15 hours ago | parent [-]

It's not my problem. It's not anyone's problem. That's my point. It's also not something that's a little further beyond the horizon or the next weakest link that attackers may target next.

fjfaase a day ago | parent | prev | next [-]

I have developing software in C(++) since 1990, but I did learn some new things about the language when developing a C compiler for a live-bootstrap variant not using the GNU Mes compiler.

noir_lord 21 hours ago | parent | prev | next [-]

It is their time to “waste” though.

charcircuit 20 hours ago | parent [-]

This thinking keeps open source behind competitors. Additionally this person is not just wasting his own time, but through both just this talk and the contents of it where he asks others for help it is causing other people to get involved with this waste of time.

noir_lord 20 hours ago | parent [-]

You seem to be missing the part where this is all people voluntarily doing things that they deem are important to themselves or just plain fun to do.

No one commands open source developers to do the things they do, they do them because they have an itch to scratch and are kind enough to release that work for other people with the same itch.

Your view is very much "What I think they should do is more important than what they think they should do" and that's not how that works.

At best that comes off as a little entitled.

charcircuit 20 hours ago | parent [-]

There are more itches for these people to scratch than this problem. Volunteer's time is both valuable and limited and it is a shame when it is wasted when those resources could have been used on something that actually makes the product better.

>"What I think they should do is more important than what they think they should do" and that's not how that works.

Again within his talk he is trying to get people to work on what he thinks is important instead of what they would otherwise be doing. Is he entitled for that? I don't think so. Trying to align people with your vision to try and accomplish things is just a part of life and I do not see it as entitlement. Society is one big optimization problem and arguments like this is a part of how the optimization process works.

markjenkinswpg 17 hours ago | parent | prev [-]

This is probably not a convincing argument, but I'll share it anyway.

Think of bootstrapable builds as a hedge against tyranny.

Is it likely that a future regime could come into being that would be backdooring FLOSS builds and undermining confidence in the entire ecosystem? Not at all likely, as this requires a purge of all the install/boot media already out there.

Though after the passage of decades, the chain of custody starts to weaken. Maybe I'll still believe in the magic of the CD in my retro closet with the three humans holding hands in a circle, but in an environment where children are told to report the thoughtcrimes of their elders, how can my nephews and nieces in turn trust me and my testimony that my copy is the "good stuff" from "the before times".

This is all very far fetched sci-fi material, but think in terms of tail risk, low probability multiplied by a high cost if comes to pass.

Perhaps a regime horrible enough to break FLOSS would be horrible enough to purge all legacy hardware and software sitting in closets, but I do think it is easier to mess up the internet and the social fabric than it is to do house to house cleanouts.

Maybe messing around with untainted FLOSS will be too dangerous in such an environment anyway, but if we can assume a state of liberty eventually returns, having a great bootstrap ready to go can help rebuild society, cyberspace, and trust on an accelerated basis.

All of this hinges on people actually auditing source code, though once you've read enough bootstrapped source to have confidence in the generation of checksums you can at least start to fall back on a social consensus as to the safety of additional source archives that have known checksums and from there also digital signatures once you've built the tools for validating those.

When it comes to "trust, but verify" of other people's source code, there is a new tool in the toolbox: large language models have demonstrated some considerable audit value. Of course almost nobody is training their own models and it's only a slightly larger circle that does inference on their own hardware or attested remote hardware, but all of this is at least something that can increase confidence when working from other folks source code.

-------

As far fetched as full on cyber tyranny sounds, its worth remembering that in North Korea this is actually reality. Folks do not have access to the internet and are handed the state built binary of Red Star OS.

The ballooning of flash drives containing western media is still a thing despite attempts to stop it.

It is unlikely that anyone will ever send in a software bootstrap, that it will get in the hands of someone who can understand it, have the time to read it and build it.

But the scenario does make us think about the value of bootstrapable FLOSS as a tyranny hedge.

Without real internet access, what good does having some freedom on a computer even do? I suppose one can keep a diary encrypted, though possessing an encrypted file is probably more of a liability than any value it provides. Someone may also find encryption helpful for friend to friend networks by sneakernet, though the downsides are considerable.

Someway, somehow the regime may fall. After decades of not trusting the outside world and being governed by a hostile state, perhaps there will be at least one deeply computer literate person to emerge from that place who will appreciate being able to bootstrap their own personal cyber citadel.

charcircuit 15 hours ago | parent [-]

This can be solved easier by having a known good Linux distribution that you make a million copies of. There is no need to start from absolute scratch if you are scared of open source code being wiped from the internet.