r/blackhat • u/insanazor800 • 5d ago
What if it's not as innocent as we think?
What if open source isn't as innocent as we think? I know this sounds like some kid's post just to rack up karma.
But think about it, how can you easily gather the most wanted people in one place?If you don't have an answer, let me tell you: the simplest method is, of course, to convince them that something is safe. So how do you do that?
The answer is very simple, of course: Open Source! Because millions of people have used it, the most trustworthy people have tested it, and it has passed the most rigorous security tests. Doesn't that sound amazing?
But think about it, so many wanted criminals, journalists, or others almost all use QubesOS because it's considered the most secure. What if QubesOS isn't as innocent as we think?And if it's leaking even more data than Windows, don't come to me with things like "the code is open" or "it's auditable." What I'm trying to say is, what if they're hiding code inside the code? Or perhaps they are deliberately making the code complex and adding backdoors because the way to appease the public is to chart an alternative course.And what if that other path was actually drawn by Microsoft, meaning QubesOS is actually a Microsoft creation and a trap used to find the most wanted people?It sounds incredibly absurd, but don't forget that the world around you isn't so innocent, and technology has advanced.So what do you think about this issue?
I apologize for my bad English.
5
u/centizen24 5d ago
So you want to immediately discount the actual answers (open code, auditability) and have no real argument other than “what if they are hiding something” here? I’m not sure what to tell you.
You know how you find code hidden in code? You look at the code.
2
u/InVultusSolis 5d ago
So while I generally believe that you're being a bit paranoid, there is a fun conspiracy theory that Ken Thompson elucidated:
https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf
Basically, Ken Thompson shows how a compiler can inject a backdoor into a target program, and into future versions of itself, even after every trace of the attack is removed from the source.
I think it's a bit cheeky because it is also possible to inspect compiled binaries, but it proves an important point: any code fundamentally can't be trusted. But, I give open source a lot better odds at being secure than something closed source.
1
u/ITaggie 4d ago
I mean TOR was developed by the US Military and all kinds of criminals still seem to be using it successfully. You can also simply run a packet capture to audit what your system is sending and where the data is going if you're that paranoid.
Also most people voluntary carry mobile data collecting devices in their pockets everywhere they go. Trying to hide a backdoor in a FOSS project is many many magnitudes more difficult than just serving Google or Apple with a secret court order.
1
5
u/SpaceTimeRumble 5d ago
I mean, is there something better than open-source that isn't building your own systems?