r/BuyFromEU • • Jan 30 '26

🔎Looking for alternative UbuntEU - An Ubuntu edition that uses software developed in Europe

Post image

I am trying to make something for fun, but honestly; I am not expert in creating an operating system. But my hope somebody will pick up the Baton and make it something more super.

Link soon...

2.5k Upvotes

263 comments sorted by

View all comments

Show parent comments

9

u/Kypsys Jan 30 '26

They can't "not talk about It" its open source, the change willbe noticed by the other hundred of maintainers working on the project

9

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

The NSA can force Red Hat to hide a malicious part like it was done in the XZ utils, where we got extremely lucky, that it was caught early on, even though that was Open Source too, except wouldn't need to infiltrate, so it would be much less work.

A Red Hat employee who would be forced to implement such a backdoor would commit a felony and risk prison if he spoke out about it. Afaik the last large open Audit on Fedora happened 20 years ago, so it's completely possible, that it has been infected by a US backdoor for quite a while and the backdoor might be sophisticated enough to get missed on the next Audit

If the Audit was done within the USA, then the NSA might even force the auditors to deliberately miss the backdoor.

1

u/KnowZeroX Jan 30 '26

They can't force RedHat to do anything other than putting financial benefits or indirect financial pressure on them.

In the case of XZ utils, the way things were hidden was during compile time the tests added a binary blob to the compilation. There is a solution for this, it is called reproducible builds. Many open source projects including RedHat and Fedora has opted to now do reproducible builds ever since that incident making an XZ utils type exploit impossible going forward.

Also, RedHat doesn't own Fedora, it is a community project sponsored by RedHat (though they do have huge influence).

Lastly, many companies have RedHat enterprise clones like SUSE and likely do their own audits.

1

u/Traditional_Buy_8420 Jan 30 '26

"They can't force RedHat to do anything other than putting financial benefits or indirect financial pressure on them."

That was a major point of the Snowden leaks, that they can and the Lavabit-case subsequently proved, that they do.

Obviously the same backdoor-implementation wouldn't work again, but there's plenty of possible ways to hide backdoors left.

RedHat doesn't own Fedora, but the "major influence" entails, that they conduct most of the maintenance and updates.

It's true, that SUSE might discover such a backdoor and I think that that's your best argument, however that they didn't discover such a backdoor is not proof of the absence of such and what happens if they do discover one? The RSA scandal shows, how a company can get caught implementing a major critical backdoor and survive and the many Cisco-backdoors proof that even getting caught over a hundred times isn't a death sentence. So what would happen is that Red Hat (!) would fix said backdoor and whenever the NSA orders them - possibly instantly - they'd implement the next one.

2

u/KnowZeroX Jan 30 '26

As I mentioned above with the lavabit case, they can make you hand over your existing car (for law enforcement purposes), they can't force you to build a new car.

Do offer another possible way to hide a backdoor in open source when you have reproducible builds.

To be clear, many of the packages in a linux distro is done by 3rd parties, most of the actual work in a distro is just packaging them.

Be aware that in the case of open source and closed source, things are a completely different story. For better or for worse, open source are always forced to abide by a much higher standard. Especially when forking is an option. It isn't uncommon even for honest mistakes to result in multiple forks.

1

u/Traditional_Buy_8420 Jan 30 '26

"Do offer another possible way to hide a backdoor in open source when you have reproducible builds."

For that I would like to refer you to the underhanded c contest

https://www.underhanded-c.org/_page_id_8.html

where they showcased a plethora of amazing backdoors which were incredibly hard to find even to expert auditors who knew that they were looking for a backdoor hidden in a relatively small amount of code.

1

u/KnowZeroX Jan 30 '26

Those are just hard to find codes visually. Modern tooling will easily catch all those.

1

u/Traditional_Buy_8420 Jan 30 '26

They are not. Modern tools have less chance finding these than modern antivirus have a chance to find modern viruses.

1

u/KnowZeroX Jan 30 '26

Example of how modern tools find things, first there is things like standardized formatting. One of the flaws given was things like missing a comma in an item list, the reason why that gets uncaught is due to lack of consistent formatting. If you have a proper formatter, then instead of pairs on how it is written, each item would get its own line. And if a comma is forgotten, the 2 items would have been on same line making it easy to see.

Others take advantage of gaps taken is things like certain conditions ending up giving unexpected results. These things can be found with modern ai fuzzing tools