this post was submitted on 07 Jul 2023
1671 points (92.9% liked)

Memes

45731 readers
1013 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
1671
It's Open Source! (lemmy.dbzer0.com)
submitted 1 year ago* (last edited 1 year ago) by [email protected] to c/[email protected]
 

Not discrediting Open Source Software, but nothing is 100% safe.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 1 year ago (1 children)

Have you ever had a look at source code or disassembly? The first is like reading a book where somebody gives the computer instructions. It's kinda readable (if you learned it) and you can figure out with 'little' effort what it's supposed to do and actually doing. Disassembly is like opening the maintenance door of a strange machine and you just see millions of moving cogs and wheels. Sure you can figure out what a single cog is for, or how a part of the machine works. But you'd have to trace thousands of movements by hand, sometimes while running. And it takes you days, sometimes weeks to do that. Even with help of quite sophisticated tools.

[–] [email protected] 1 points 1 year ago (1 children)

You're right there is a difference in effort. That said source code can also be obscure if you are trying to hide something. Behavioural analysis at runtime is effective no matter what, but it typically doesn't tell anything about code coverage.

[–] [email protected] 1 points 1 year ago

Sure. You can try to sneak something in that isn't obvious. But you can also try to evade behavioural analysis. Not load load your malicious code if you detect you're running inside a virtual machine. Stop sending packets if some sniffer software is installed, only send data every 2 months, etc... It's an arms race, either way.

Regarding 'a difference in effort': Idk. It's a pretty big difference. You could also call taking a plane to fly to hawaii for two weeks or swimming there - a difference in effort. And while there might be one or two outliers with obscure code, the majority will be kind of readable. But i agree. You have to be intelligent, pay close attention if somebody tries to sneak something in in plain sight, know how you could be tricked and use multiple tools and approaches simultaneously, to be effective.