In response to the Snowden revelation that the CIA compromised Apple developers' build process, thus enabling the government to insert backdoors at compile time without developers realizing, Debian, the world's largest free software project, has embarked on a campaign to to prevent just such attacks. Debian's solution? Reproducible builds.
In a talk at Chaos Communication Camp in Zehdenick, Germany, earlier this month (full text here), Debian developer Jérémy Bobbio, better known as Lunar, told the audience how the Linux-based operating system is working to bring reproducible builds to all of its more than 22,000 software packages.
Reproducible builds, as the name suggests, make it possible for others to reproduce the build process. "The idea is to get reasonable confidence that a given binary was indeed produced by the source," Lunar said. "We want anyone to be able to produce identical binaries from a given source."
"We are not discussing a hypothetical attack here."
A software package reproducibly built should be byte for byte identical to the publicly-available package. Any difference would be evidence of tampering.
"The great thing with free software is that we have the freedom to study the source code," he said. "That it does not contain any malware, malicious code, or security bugs."
But how, Lunar asked, do we know that the compiled binary was built from the published source? How do we know the CIA, or other malicious attacker, has not tampered with the build process?
"We are not discussing a hypothetical attack here," he said. "This is a real attack. We are talking about developers in totally good faith producing software, the binary they would give you, and even if they are of good faith, we could be totally owned."
Reproducible builds are already a staple of Bitcoin and the Tor Project. Many other free software projects, including FreeBSD, NetBSD, and OpenWrt, are moving in the same direction.
"This is a bad thing for the CIA and a good thing for us," Lunar said.
https://archive.is/QyT1M
http://motherboard.vice.com/read/how-debian-is-trying-to-shut-down-the-cia-and-make-software-trustworthy-again