Horde backdoored
dev.horde.org
dev.horde.org
What are the possibilities that such code could make its way into some piece of extremely popular public facing software, say Apache? How many cleverly hidden "bugs" already exist that open us up to complete pwnage for the clever bastard behind them?
Just think about the havoc someone could do with a few popular but nasty PyPi or RubyGem packages...
All those developers use VCS repositories, not the releases distributed through FTP sites and such -- which were the files affected here.
MD5 hashing is currently used to give quick and simple check on transmission download errors, rather than malicious attacks.
>The same goes for "verified" binaries, packages, etc... apparently that is not always the case.
If proper package signing was in place, like most modern distros support, then this couldn't have happened. The backdoor was not in the main code in SVN or in Git, which specifically protects against this exact problem, but added to unprotected releases dumped on a server.
>What are the possibilities that such code could make its way into some piece of extremely popular public facing software, say Apache?
No bad code was added to the code base.
Pedant alert, but Subversion doesn't protect against malicious manipulation; it doesn't checksum its commits.
He wrote this right after demonstrating how to create, step-by-step, an undetectable trojan horse in the C compiler. Here are the steps for creating such a trojan horse:
http://cm.bell-labs.com/who/ken/trust.html
[ Also see http://news.ycombinator.com/item?id=2642486 ]
What's the best way for open source projects to make it easy for their customers to get verified downloads? A lot of packages post MD5 checksums but no one tests them when downloading manually, do they? Automated signature checking on Debian packages seem to work better in practice; homebrew also verifies download checksums automatically.
Idea: protocol- and package-format-independent verification of packages, with trust rooted in DNSSEC of the ultimate source domain using DANE.
git has pretty good signatures for tags. Maybe there's a way to leverage that for secure open source distribution.
1. Have to control the signature that's provided 2. Have to have a trust system in place so that people realized that the signature provided wasn't legit.
I'm not sure the personal public key infrastructure (web of trust) is developed enough to absorb that.
These distros are distributed with a keychain that contains keys for all the approved developers/uploaders. What you have to trust is the fact that the keychain you have is the real one, but that is easy to do. Once you trust your keychain you can install things securely: the private pairs are in hands of people that have been through processes similar to this http://www.debian.org/devel/join/newmaint .
It's sort of a chicken and the egg problem, PGP. A better web of trust would help resolve these issues (I'm probably not that many trusted steps from a Debian developer), but without a better web of trust, it's hard to build a web of trust, if that makes any sense.
And it seems no one does key signing parties any more...
The affected releases are:
- Horde 3.3.12 downloaded between November 15 and February 7
- Horde Groupware 1.2.10 downloaded between November 9 and February 7
- Horde Groupware Webmail Edition 1.2.10 downloaded between November 2 and February 7
I've happily used Horde for well over 5 years. I was really really looking forward to Horde4. Once it came out, I immediately tried it. Tried to install it, that is. I failed. The lack of clear documentation combined with the dark magic of php-pear kept me from migrating. And even when I did get it installed I was unable to comprehend the UI. It completely changes depending on what 'application' you're using. There is no consistency.
E.g.: The calendar in Horde4. The interface completely changes into nothing you've ever experienced. It's unrecognisable from the rest of Horde4.
I migrated to RoundCube + Plugins for calendar (caldav+davical) and addressbooks (carddav + davical) and have been a happy, android syncing camper ever since.
The UI is currently undergoing a rewrite, but the default interface can be forced into the traditional view in the Horde configuration.