Mozilla: Firefox Has No Government Backdoors

Status
Not open for further replies.

Estix

Honorable
Apr 12, 2012
250
0
10,810
Is Mozilla trying to say Firefox is safe from government agencies inserting code into their program because they are open source? I guess they haven't heard of SELinux.http://en.m.wikipedia.org/wiki/Security-Enhanced_Linux
No, that wasn't what they were saying; they were saying that, because they are open source, the source can be audited, and then verified as safe, by comparing an "expected" compiled binary to the actual distributed one - that is, by making sure that, as the article said:
"To ensure that no one can inject undetected surveillance code into Firefox, security researchers and organizations should regularly audit Mozilla source and verified builds by all effective means, establish automated systems to verify official Mozilla builds from source, and raise an alert if the verified bits differ from official bits,"
 

qlum

Distinguished
Aug 13, 2013
195
0
18,690
It is never a 100% secure way as backdoors can very well be hidden in legit additions to the browser and chances are in such cases that a government manages to insert backdoors but I still think its pretty backdoor free if only for the fact that attempting to add a backdoor and failing would be very problematic and the chance of someone finding it out is always there. Still if a clever coder manages to put it in and it gets past screening there may still be backdoors in firefox.
 

Cleber Zarate

Honorable
Jan 19, 2014
1
0
10,510
Validating that the compiled binary is the exact same binary produced if you compile that code yourself can be a very tricky task, first because your compiler version and every library used might make a difference in the resulting binary, the second is because there's no good way for them to ensure us the own firefox download servers that we use to download firefox isn't tampered to offer different binaries and md5s to different IP addresses or something. I know this might be unlikely but hey, didn't we all think unlikely that the whole NSA deal could take place?
 

s32ialx

Honorable
Jan 20, 2014
1
0
10,510
Well we've lost the fight and the big ISP's can control what we view on the net.http://www.wired.com/opinion/2014/01/internet-freedom-day-year-net-neutrality/
 
Status
Not open for further replies.