[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Proxy support in apache
Ira Abramov wrote:
>
> On Mon, 11 Aug 1997, Amos Shapira wrote:
>
> > |you can TRUST a binary you compiled yourself from original sources better.
> >
> > The fact that YOU trust such privatly-compiled binaries just because
> > you personally typed "make" doesn't mean anything. People trust
> > source code when they read it and look for trojan hourses and security
> > bugs - did you ever look the Apache source for such holes? If not
> > then what makes you more comfortable with your own binary?
>
> because I know the sources came from the original site and not from
> redhat's "contrib" directory, to which people have already uploaded
> bad binaries in the past (afaik, they found them all, they check more
> closely now) or even altered sources before uploading (not all for
> malicious reasons!)
Why do you trust the source on the original site? Do you check them?
Why don't you suspect that someone could upload a bogus source there
too? It's a possibility.
> > Ira, don't get me wrong, I don't mind you doing anything with your own
> > computer, but I don't like to see the spread of what are in my view
> > false practices in the Linux community. If you give me a good reason
> > to justify your recommandation then I'll shut up about this.
>
> like I said, a new NCFTP I would probably trust, but a daemon that runs on
> my server, which is open for hits from the net (and maybe runs as root) is
> a reason to recompile from the original site's sources. I gave ssh, apache
> and squid as examples because they are popular apps, and the RPM contrib
> directories might have them with trojans for all I know. call me a
> paranoid.
Paranoia in this context is healthy, but you might be fooling
yourself if you think that you are safe just because you download
the source and compile it yourself, without proof-reading it or
doing some reliable checks that it is indeed the original source.
You just seem to waste your resources with no real gain. (full-gas
in neutral?)
Be paranoid - but do it right.
--
--Amos Shapira | "Of course Australia was marked for
133/13 Shlomo Ben Yosef st. | glory, for its people had been chosen
Jerusalem 93 805 | by the finest judges in England."
ISRAEL amos@gezernet.co.il | -- Anonymous
References: