16 ms·
National Security letters for open source code ? Or is it for just the private repositories ? Or is it to be able to "subtly add code" to existing repositorie
by balls2you 11y ago
National Security letters for open source code ?
Or is it for just the private repositories ?
Or is it to be able to "subtly add code" to existing repositories without being seen ?
What would it be for ? I am stumped.
- diminoten 11y ago> Or is it for just the private repositories ? That. Relax. > Or is it to be able to "subtly add code" to existing repositories without being seen ? Come on now, this is not productive to speculate on. This is "the CIA is controlling the population by putting chemicals in your water supply!" level stuff.
- celsoazevedo 11y agoSome people said the same about NSA, but now we know that they do "hard to believe" stuff.
- diminoten 11y agoThat's some specious logic, at best.
- celsoazevedo 11y agoSo, according to you, they (agencies from US, China, Russia, etc) never cross lines that you and me would never cross? They never tried to broke security, sabotage, ..., or hack someone? I'm not talking about moon or UFO's conspiracies. I'm talking about things that, according to leaks and official documents, they already did in the past and keep doing today.
- diminoten 11y ago> I'm talking about things that, according to leaks and official documents, they already did in the past and keep doing today. Please cite an official document that shows the US government forcing GitHub to secretly modify the source code of a project in one of its repos. As far as I'm aware, they've literally never done that, and to suggest they have means you have to show evidence that such a thing has taken place. This is some Fox News level bullshit. "How do we know the FBI hasn't raped and murdered a girl in 1990? They've never come out and specifically stated they haven't!"
- celsoazevedo 11y agodiminoten, you started by comparing one of @balls2you questions to a plan/plot/conspiracy. I commented saying that just because it's something you think that no government would ever do, doesn't means that they don't do it. I compared it to the NSA leaks, because until Snowden, everyone that talked about NSA (and other agencies) controlling the internet was called crazy. Now we now that those guys weren't that crazy. I'm not saying that the US (or other country) government did change some code on some repo on Github, what I'm saying is: if they want, they can do it legally or illegally. Do you understand my comment now?
- diminoten 11y agoI've always understood your comment, what I don't agree with is the need to state it now. When we make statements, we do so with context, and in this context, stating "the US government could do X" is implying that, yes, in fact the US government did do X. Furthermore, saying "we don't know they didn't" is a specious argument, at best, because it suggests they did do X, when in reality they're no more likely to have done X, than I am to have done Y, which is some arbitrary other thing which is, while in the realm of possiblity, a complete waste of time to consider. There exists, within the set of possible things, a set of things which are not among the greater set of things one must consider. The US government secretly forcing GitHub to modify source code in one of their repositories is one of those things that we can safely not consider, even though it is, you're right, technically and politically possible.
- mikekchar 11y agoOn the other hand, consider a computer system. If you wish to have a secure computer system, you try to design it in such a way so as to make undesired behaviour impossible. For example, we spend a lot of effort looking at weaknesses in our systems and saying, "Well, someone could overflow this buffer here and get root access". Our reasoning is that if it is possible, it is probably only a matter of time before someone actually exploits it. So while I completely relate to your feeling of trying to avoid conspiracy theory fantasies of "how do we know they haven't done that", I think it is probably not a good idea to say, "[this] is one of those things that we can safely not consider, even though it is... technically and politically possible". Whether or not it has happened in the past, we probably don't want it to be possible and we probably should consider to consequences of what would happen if the government decided to take that action. 'Eternal vigilance is the price of liberty,' and all that rot.
- MCRed 11y ago"Good germans," even years after war, were certain there's no way their government could have perpetrated something like the holocaust and were convinced it was just allied propaganda. Hence the phrase "good germans" for people who believe anything the government tells them, without question, despite the history of government criminal activity, pretty much nonstop going back to the revolution. (Hell, imposing the constitution was done by a coup, there was no mechanism for replacing the prior government, so they just did it with fait accompli. That said, I wish we operated under that constitution, then there would be no need for these reports to reveal just how many people's (in bands of 250) constitutional rights are being violated.)
- diminoten 11y agoAre you fucking kidding me, I'm now a Nazi German because I don't believe the US government forced GitHub to secretly edit one of their repos? This place, good fucking grief.
- Karunamon 11y agoAnd we have evidence of those things. This is something else. Basic rationality demands that we not treat something as truth until we have evidence of it. The existence of bad actors does not mean an abandonment of critical thinking! Critical thinking in this case tells us that compromising a git repo is a horrible idea, mostly because even if you broke SHA and even if you managed to slip the code in undetected, the jig is up the moment somebody makes a conflicting change in that file, wonders what's going on, and then discovers that the server copy does not jibe with the local copy.
- celsoazevedo 11y agoAnd I agree with you. But we can't blindly defend governments, agencies or countries and attack someone just because their opinion or ideia doesn't fit on the "official version". There is also a big deference between what I did (considering the ability to do something) and accuse them of doing something. You don't need evidence to think if they can or not do it.
- celticninja 11y agothe thing about that claim is that they did try (LSD in drinking water as part of MKULTRA), that it didnt work doesnt really matter, if they thought they could again you could bet your bottom dollar that they would try again.
- diminoten 11y agoRight. And I don't suppose you know where Hoffa's body is buried, do you?
- charonn0 11y agoIt sounds like conspiracy theorist fodder, but it's not: http://www.intelligence.senate.gov/pdfs/95mkultra.pdf http://www.intelligence.senate.gov/pdfs/95mkultra.pdf
- diminoten 11y agoThe combined letters "water" shows up in that text 7 times. In all but one of the cases, it's because of Senator Barry Goldwater's name is in the report. In the remaining case (the only time the word 'water' itself shows up) is this sentence: > One police writer claims that the threat of scopolamine interrogation has been effective in extracting confessions from criminal suspects, who are told they will first be rendered unconscious by chloral hydrate placed covertly in their coffee or drinking water. Which is absolutely unrelated to putting chemicals in the drinking supply of a population in an attempt to mind control them.
- rmxt 11y agoTry searching for "unwitting". I think it's completely fair (and true) to state that past government programs tested chemicals on unwitting Americans and foreigners. Might not have literally been attempts at "mind-control" or "tainting water supplies with psychedelics", but misdirection and abuse of power definitely occurred and continues to occur. "In order to meet the perceived threat to the national security, substantial programs for the testing and use of chemical and biological agents-including projects involving the surreptitious administration of LSD to unwitting nonvolunteer subjects "at all social levels, high and low, native American and foreign"-were conceived, and implemented. These programs resulted in substantial violations of the rights of individuals within the United States." pg. 73 (393) See also: https://en.wikipedia.org/wiki/Frank_Olson https://en.wikipedia.org/wiki/Frank_Olson
- joshkpeterson 11y agoRelax? You've got to be fucking kidding me.
- Amorymeltzer 11y agoIt could be for non-public information, could it not? Private repositories are one obvious, but hidden email addresses and IPs could easily be targets. And maybe they want the public information but in an easy-to-manage format. When you've got the tools, it's probably easier to say "Give us every commit log entry for these ten users" rather than go search for it yourself.
- wongarsu 11y ago> And maybe they want the public information but in an easy-to-manage format Would there be any legal requirement to satisfy such a request? Why should a business expend resources to do something the police could do on their own?
- danso 11y agoVarious freedom of information laws acknowledge the importance of information being provided to the requester in a machine readable format, when that information originates from such a system. I'm not arguing that this applies to police asking a private entity for information, just that the courts/regulators are not ignorant about the difference between machine-readable data and "oh just do a search and copy-paste it from the website". http://www.justice.gov/oip/blog/foia-post-2009-annual-foia-reports-machine-readable-format http://www.justice.gov/oip/blog/foia-post-2009-annual-foia-r... http://sunlightfoundation.com/blog/2014/08/25/freedom-of-information-tools-its-time-for-an-open-data-inspired-upgrade/ http://sunlightfoundation.com/blog/2014/08/25/freedom-of-inf...
- Lawtonfogle 11y ago>Various freedom of information laws acknowledge the importance of information being provided to the requester in a machine readable format, Such as an XML(ish) markup with accompanying code to describe presentation?
- ckuehl 11y agoAs an interesting example, Lavabit tried handing over their RSA private keys in an illegible printed font: https://nakedsecurity.sophos.com/2013/10/04/cheeky-lavabit-did-hand-over-encryption-keys-to-us-government-after-all/ https://nakedsecurity.sophos.com/2013/10/04/cheeky-lavabit-d...
- Igglyboo 11y agoHow would you subtly add code to repositories without breaking git?
- revelation 11y agoBy breaking SHA1, obviously.
- jasonmp85 11y agoAnd if people actually signed their commits and tags?
- erdeszt 11y agoCommit hashes are not a security feature but you can sign your commits with gpg.
- wongarsu 11y agoSome projects sign their release commits and tags, some even their merge commits, but I have never seen a project which actually signs every commit. The reasoning is always that you are actually signing the whole commit chain because your commit is liked to every previous one by the commit hashes.
- erdeszt 11y agoTrue but I was just mentioning the possibility not the best practices for using it.
- wongarsu 11y agoBy breaking SHA1 you could covertly edit older commits, but existing contributors would still have the original version. As soon as somebody edits code at the intrusion it would be discovered because it would merge cleanly locally but cause a merge conflict on github. Of course on big projects a lot of the code isn't touched in years but we're talking about revealing that somebody broke SHA1. It sounds very risky given the stakes.
- pc2g4d 11y ago> Or is it to be able to "subtly add code" to existing repositories without being seen ? I don't think it's this---I understand it to be basically impossible to mess with git repository histories without people noticing. I guess they might try to sneak it in as a new commit, but hopefully others on the project are inspecting things???
- MCRed 11y agoGit commits are hashes of the patches, right? So, while it would be difficult to change the blockchain of bitcoin because its widely distributed and computationally expensive, it wouldn't be too hard to do it to git. Process would be something like: -- Take the original chain. -- Identify a patch in the past where you want to insert the code -- Check out back to that patch -- Make the change -- Roll forward with all the following patches re-applied (with new hashes of course) -- Replace the repo with the new repo. The end result is that hashes would change. So if you were talking to people about a particular patch using its hash, or telling people a particular release is set at a particular hash, you would notice when this changes. So it wouldn't be invisible using this method. An alternative approach might be to generate a series of innocuous code changes that will produce the end result of restoring the hashes of the latest commit to what they should have been before the change. This might be extremely difficult or computationally intensive, unless the hash algo is weak. But it seems theoretically possible, unless I'm missing something about how git works.
- paulannesley 11y agoThat's what `git rebase --interactive` does (which has been described as being “a bit like git commit --amend hopped up on acid and holding a chainsaw–completely insane and quite dangerous but capable of exposing entirely new states of mind”[0]) The scenario described happens frequently when people `git push -f` a rebased tree, and it certainly does not go unnoticed by other developers on the project — more “havoc” than “subtle”. [0]: http://2ndscale.com/rtomayko/2008/the-thing-about-git http://2ndscale.com/rtomayko/2008/the-thing-about-git
- shin_lao 11y agoYou could use git to exchange information securely via SSH or also gist.
- emergentcypher 11y agoProbably for the account details of people accessing certain repositories. For example: account information, access logs, IP addresses, relating to the Tor project's managers, contributors, downloaders, etc etc.