• FizzyOrange@programming.dev
      link
      fedilink
      arrow-up
      3
      ·
      17 hours ago

      That would be good but it’s not a magic solution to this problem. They would just move the exploit to runtime. Yeay you don’t get hacked if you compile and never run your program.

      You can counter that there are some situations where the program is run sandboxed, e.g. if you’re compiling to WASI or microcontroller firmware or whatever. But those are a tiny minority of cases.

    • TehPers@beehaw.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      There have been discussions in the past around sandboxing build scripts, but until that day comes (if it does), I think there could at least be a prompt to approve build scripts for individual package versions. Several JS package managers do this now, and it helps.

    • sik0fewl@piefed.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Ya, this type of design (npm, Rust, Go?) seems crazy to me. I’m glad I use Java in my day job, haven’t run into any build script attacks yet.

      I guess Rust probably chose it so you can build easily on any system? But why can build scripts download stuff an me inject it?

      • deadcream@sopuli.xyz
        link
        fedilink
        arrow-up
        3
        ·
        19 hours ago

        It’s necessary to integrate Rust with other languages (to build source code in other languages, generate some bindings, etc). Otherwise you will have to make Cargo understand every other build system in existence, and stay compatible with them forever.

        Ideally this should be heavily audited and allowed only when it’s really necessary.

      • ISO@lemmy.zip
        link
        fedilink
        arrow-up
        8
        ·
        1 day ago

        Almost all non-trivial projects in any language have external dependencies. And those dependencies have to come from somewhere.

        I also wonder what you think Maven/Gradle/…etc job is.

        • sik0fewl@piefed.ca
          link
          fedilink
          English
          arrow-up
          3
          ·
          edit-2
          15 hours ago

          Gradle and Maven create static build artifacts, they do not dynamically run 3rd party build scripts. And it is uncommon (though not impossible) to use dynamic version targets.

          I’m it not saying it’s an impossible attack vector Java, but I haven’t seen it yet and I’ve seen it a couple times with Rust and countless times with Javascript. The Javascript ones now use your credentials to publish even more malicious build scripts, so it spreads like a virus.

          • deadcream@sopuli.xyz
            link
            fedilink
            arrow-up
            3
            ·
            19 hours ago

            In Java world package managers and package registries work with prebuilt libraries because for JVM bytecode it’s sufficient. And if they have native dependencies then they include compiled .dll or .so files that are built on developer’s machine. This makes things simpler but has its own drawbacks (these dependencies work only on architectures and OSes developer thought of, there is no guarantee that the library will be compatible with user’s environment, etc).

            In Rust world everything is built from source, including native dependencies. Thsi makes build process much more complicated and necessitates running code on user’s (developer consumes the library as dependency, not end user) machine to build everything that’s not Rust.

            • badmin@lemmy.today
              link
              fedilink
              arrow-up
              1
              arrow-down
              1
              ·
              16 hours ago

              I just wanted to ask, how do they build C libraries in JAVA world? And if the answer is they don’t, they just ship binaries, then that’s infinitely worse. And you just confirmed that’s the case 😲😄.

              • sik0fewl@piefed.ca
                link
                fedilink
                English
                arrow-up
                1
                ·
                14 hours ago

                In reality it very rarely happens that native binaries are needed for Java. I’m not even sure what libraries might use them nowadays - I would guess mostly commercial closed source.

                I don’t think it’s “infinitely worse”, but it does mean you require builds for whatever platform you are on or you need to manually build it from source as a separate project.

                • badmin@lemmy.today
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  14 hours ago

                  JVM, ELF, Mach-O,… binaries are infinitely worse when the attack vector is “compromised dev machine”.

                  I’m not sure how anyone would even try to argue against that.