Everyone takes it for granted that the github link on an npmjs.com project page describes the code you get when you `npm install`.
Both npmjs.com and the Chrome app store should have an in-line file browser to make it as easy to vet the code as possible.
I have a browser plugin[0] that lets you view a Chrome plugin's source code, but I've also noticed how many of them obfuscate their code. For example, the Super Netflix plugin is heavily obfuscated: https://chrome.google.com/webstore/detail/super-netflix/aioe...
I can certainly imagine why. It would take me a non-trivial amount of time to figure out how to interact with Netflix's client/server. I gave up when I couldn't even figure out how to programmatically pause/unpause the client. And that's now the plugin's secret sauce, especially in a hostile app store where everyone is chomping at the bit to clone your plugin.
I don't know of any easy solutions here.
Even large scale manual review like Apple's approach has issues with clones.
[0]: https://chrome.google.com/webstore/detail/chrome-extension-s...
Eclipse and PyPy has a problem with it too[0][1].
Apple with their walled garden also isn't a panacea. They let a very glitchy and broken version of cuphead onto the app store (so much for manual review and flawless experience) and there apparently is a known repeated offender whose MO is to port popular indie desktop games (maybe because it's Unity3D games it's easy?) to iOS hastily and sell them[2]. They also only last year banned the fake anti-viruses (the "speed your phone up by clicking this red button in this free app and paying us $10 to remove 1337 north korean backdoors, viruses and unneeded programs!1" clickbait kind, the one that targets low tech people).
I also wonder how far you could maybe get with some really great game in a native executable for Windows on itchio or Game Jolt (or maybe even on Steam, they are really bad with catching broken, bad, etc. games and have a very hands off approach to everything on there) that was also packed with covert viruses/trojans, people download and run those very willy nilly on their computers, don't keep themselves up to date (thanks to Microsoft making updates obnoxious and doing crap like installing Candy Crush 325254th time, I know I removed one from my laptop like twice or thrice now) and I wonder if there is any security scanning on those sites to try detect viruses in uploaded files (I wanted to try with EICAR but it kept getting nuked by Windows Defender and I don't have the patience to try make it leave my EICAR file alone).
[0] - https://eclipse.org/org/press-release/20170814_security_bull...
[1] - https://news.ycombinator.com/item?id=15256121
[2] - https://www.polygon.com/2017/12/18/16790052/cuphead-fake-ios...
[3] - https://www.theverge.com/2017/9/15/16314034/apple-developer-...
I also meant Chrome extensions of course, not plugins, but plugins are so rare (except the default Flash) and sidelined (even chrome://plguins no longer works) that I call extensions plugins very often.
A diff with an X or a check mark if it's overall different in any way would be awesome too.
Unfortunately, in reality you quickly run into problems with different compiler versions, optimisation settings and other issues that make builds unreplicable. At least with chrome extensions you can look at the JS source. With ethereum, all you have to go on is the compiled bytecode.
This was one of the interesting use cases I thought about when I dug into crypto.
As evinced by the article, the web store isn't perfectly trustworthy but this kind of validation could be done automatically and I do trust their ability to automate.
but that's just a roundabout way of doing reproducible builds.
Having one homogeneous decentralized way to read this data is neat. You could make entire package managing solution out of this. Even attach torrent magnet links for each lib in the chain, and make the whole store distributed.
It would be a fair point to say that if you don't trust any specific person or entity to verify that a given source compiles to the binary signed by the author that maybe some sort of blockchain would be useful. I think you'd get a lot more bang for your buck by using trusted authorities in something closer to a CA model.
And you do need trust for distributing software.
You can't use git, it's hard to sync automatically. Torrent is a nice transport, not a db, and can be use to sync blockchains anyway, why make them exlusive ? And using any distributed db would exclude the field tested solution on millions of wallet that prove to work, and the api that is alreay well supported.
Why would you need a blockchain for this?
Evil insiders.There are two threat models:
1. Evil Foreign Spy infiltrates the Tor project and makes a backdoored, signed release.
Evil Foreign Government uses MITM or something similar to serve this backdoored version to one or two journalists they know aren't technical enough to inspect the source code themselves.
The journalists think "This will be safe, as it will have been code reviewed by people who know how to do that" but no such people ever saw the backdoored version.
Hence, you don't just need a signed build - you also need a globally-agreed list of builds, so the user (and the auto-update mechanism) can be sure everyone else in the world knows this release exists. If a build is ever repudiated, sound the alarm!
2. Evil Foreign Spy infiltrates the Tor project, and intentionally triggers the alarm in a way that doesn't lead back to them.
The alarm going off and the fact the infiltrator hasn't been found means people don't trust Tor, or they start ignoring the alarm rendering it useless.
Hence, you don't just need a globally-agreed list of builds - you need an indestructible, globally-agreed copy of each build's source code and who changed each line.
Now granted, a blockchain isn't the only way to achieve these things - indeed, it'd cost a fortune to put the entire Tor source code into the Bitcoin blockchain - but you need some similar mechanism.
... sorry had to post this. Quite tired of Blockchain.
My own strategy is just to limit the number of extensions I use to a small number of ones from established/trusted entities, but it pains me because I publish a couple extensions and I am not an established entity.