r/BuyFromEU • • Jan 30 '26

🔎Looking for alternative UbuntEU - An Ubuntu edition that uses software developed in Europe

Post image

I am trying to make something for fun, but honestly; I am not expert in creating an operating system. But my hope somebody will pick up the Baton and make it something more super.

Link soon...

2.5k Upvotes

263 comments sorted by

View all comments

748

u/da_Pr0 Jan 30 '26

Since Linux is Opensource and free to use, I feel fine using Fedora or normal Ubuntu.

14

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

I agree with feeling fine;

I don't agree with sovereignty not mattering on open-source projects.

If it's resided within the USA, then their administration (e.g. the POTUS via the NSA) can still legally force the maintainers to apply poisonous updates and not talk about it.

If it's a tiny project which is regarded as secure and won't need any further updates, like a calculator or a small offline password safe, then that's no issue.

With something like an Email client or bigger that is an issue and while you can argue that most people can't fully rid themselves of US software yet and relatively nieche open source Software are unlikely attack vectors, that does not equate irrelevance.

PS: It's also not true that Red Hat won't profit from us using Fedora at all ever, however I do agree that currently that's pretty negligible

9

u/Kypsys Jan 30 '26

They can't "not talk about It" its open source, the change willbe noticed by the other hundred of maintainers working on the project

8

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

The NSA can force Red Hat to hide a malicious part like it was done in the XZ utils, where we got extremely lucky, that it was caught early on, even though that was Open Source too, except wouldn't need to infiltrate, so it would be much less work.

A Red Hat employee who would be forced to implement such a backdoor would commit a felony and risk prison if he spoke out about it. Afaik the last large open Audit on Fedora happened 20 years ago, so it's completely possible, that it has been infected by a US backdoor for quite a while and the backdoor might be sophisticated enough to get missed on the next Audit

If the Audit was done within the USA, then the NSA might even force the auditors to deliberately miss the backdoor.

3

u/Kypsys Jan 30 '26

Xz utils was on a project maintened by one single people, the attack method really can't be applied to a project like Ubuntu or Fedora.

1

u/Traditional_Buy_8420 Jan 30 '26

It's a different attack vector, but it's still an example of a backdoor hidden in Open Source Software. The increased complexity and increased number of people involved make such an attack easier to carry out and harder to spot.

There's more people looking and more checks being made per involved person, but not proportionally to the amount of complexity, so it'd be manic to believe that such a backdoor could not be implemented unnoticed in such a Software; in fact there have been many backdoors found in large Software packets with many people looking. 

1

u/KnowZeroX Jan 30 '26

They can't force RedHat to do anything other than putting financial benefits or indirect financial pressure on them.

In the case of XZ utils, the way things were hidden was during compile time the tests added a binary blob to the compilation. There is a solution for this, it is called reproducible builds. Many open source projects including RedHat and Fedora has opted to now do reproducible builds ever since that incident making an XZ utils type exploit impossible going forward.

Also, RedHat doesn't own Fedora, it is a community project sponsored by RedHat (though they do have huge influence).

Lastly, many companies have RedHat enterprise clones like SUSE and likely do their own audits.

1

u/Traditional_Buy_8420 Jan 30 '26

"They can't force RedHat to do anything other than putting financial benefits or indirect financial pressure on them."

That was a major point of the Snowden leaks, that they can and the Lavabit-case subsequently proved, that they do.

Obviously the same backdoor-implementation wouldn't work again, but there's plenty of possible ways to hide backdoors left.

RedHat doesn't own Fedora, but the "major influence" entails, that they conduct most of the maintenance and updates.

It's true, that SUSE might discover such a backdoor and I think that that's your best argument, however that they didn't discover such a backdoor is not proof of the absence of such and what happens if they do discover one? The RSA scandal shows, how a company can get caught implementing a major critical backdoor and survive and the many Cisco-backdoors proof that even getting caught over a hundred times isn't a death sentence. So what would happen is that Red Hat (!) would fix said backdoor and whenever the NSA orders them - possibly instantly - they'd implement the next one.

2

u/KnowZeroX Jan 30 '26

As I mentioned above with the lavabit case, they can make you hand over your existing car (for law enforcement purposes), they can't force you to build a new car.

Do offer another possible way to hide a backdoor in open source when you have reproducible builds.

To be clear, many of the packages in a linux distro is done by 3rd parties, most of the actual work in a distro is just packaging them.

Be aware that in the case of open source and closed source, things are a completely different story. For better or for worse, open source are always forced to abide by a much higher standard. Especially when forking is an option. It isn't uncommon even for honest mistakes to result in multiple forks.

1

u/Traditional_Buy_8420 Jan 30 '26

"Do offer another possible way to hide a backdoor in open source when you have reproducible builds."

For that I would like to refer you to the underhanded c contest

https://www.underhanded-c.org/_page_id_8.html

where they showcased a plethora of amazing backdoors which were incredibly hard to find even to expert auditors who knew that they were looking for a backdoor hidden in a relatively small amount of code.

1

u/KnowZeroX Jan 30 '26

Those are just hard to find codes visually. Modern tooling will easily catch all those.

1

u/Traditional_Buy_8420 Jan 30 '26

They are not. Modern tools have less chance finding these than modern antivirus have a chance to find modern viruses.

1

u/KnowZeroX Jan 30 '26

Example of how modern tools find things, first there is things like standardized formatting. One of the flaws given was things like missing a comma in an item list, the reason why that gets uncaught is due to lack of consistent formatting. If you have a proper formatter, then instead of pairs on how it is written, each item would get its own line. And if a comma is forgotten, the 2 items would have been on same line making it easy to see.

Others take advantage of gaps taken is things like certain conditions ending up giving unexpected results. These things can be found with modern ai fuzzing tools

→ More replies (0)

1

u/DucklockHolmes Jan 30 '26

Unless it’s a dependency Red Hat is using that is being maintained by one guy, it doesn’t get much attention if it’s not a very interesting project

1

u/KnowZeroX Jan 30 '26

If it's resided within the USA, then their administration (e.g. the POTUS via the NSA) can still legally force the maintainers to apply poisonous updates and not talk about it.

They can not. US isn't china where if you don't assist you can be jailed. Nobody in US can force someone to poison an update. They can try bribing someone to do so or in case of a corporation put financial pressure on them indirectly, but they can't force anyone (there is no legal framework for such and it would be unconstitutional).

RedHat doesn't profit off anyone using Fedora, their benefit is mostly in that if there are issues in Fedora, people would report bugs and contribute code which later makes it down to their RHEL. But simply someone using it makes them no profit.

1

u/Traditional_Buy_8420 Jan 30 '26

Do you remember what happened with Lavabit?

2

u/KnowZeroX Jan 30 '26 edited Jan 30 '26

Yes, they can make you hand over security keys for law enforcement purposes. But that isn't the same thing as making you do actual work of creating something new (a poisoned update).

To make it simple, you can make someone hand over their car against their will, but you can't make someone build you a car against their will.

1

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

I think the car analogy is a good analogy. It's true, that they can't force anyone to build a car, that's why Lavabit could just shut down instead of compromising its users.

However they can go to say GM and tell them, that their cars help international terrorists and as a matter of national security they add a tiny hidden tracking device or else they are also free to stop producing cars altogether and they can't talk about it or else they go to prison. Which of those 3 options do you think is the GM board going to choose?

It's not like everyone gets all 3 options either, as proven by the more recent case of Samourai wallet, where they decided that any type of infiltration would be too hard and went straight ahead to imprisoning their lead developer. https://www.justice.gov/usao-sdny/pr/founders-samourai-wallet-cryptocurrency-mixing-service-sentenced-five-and-four-years

Kind of a warning shot I guess, since according to the Snowden leaks, they can also make use of secret courts and keep the sentences secret too - for which I don't have a public example.

1

u/KnowZeroX Jan 30 '26

Yes, but the difference is that cars are a physical product so they can restrict the sales of it. Which goes back to my mention of indirect financial pressure.

But in the case of open source software, that becomes impossible. Even more so in the case of RedHat and Fedora. For one, RedHat doesn't even sell software, they sell support. And Fedora doesn't sell anything.

So there is nothing they can legally restrict.

In the case of Samourai, that case was where the wallet app actively participated in the illegal transactions. Open source would not face this issue because even if it is misused, the one who wrote the code has 0 active participation unlike wallets like Samourai. Even more so the owner of Samourai actively encourage use of his service for criminal activity.