Portál AbcLinuxu, 12. května 2025 16:45
Tohle je z principu špatně. Software by po síti neměl vůbec nijak komunikovat, pokud si to uživatel explicitně nepřál. Viz kapitola Network interactions v Sane software manifesto:
- Network connectivity must not be required during build – the build must be possible completely offline. All dependencies must be downloadable and documented including secure hashes or preferably cryptographic signatures.
- If dependencies are optionally automatically downloaded during or before build, the packaging system must cryptographically verify that that they are undamaged.
- Avoid unwanted network interactions during runtime. There must be no „call home“ or update-checks without user's explicit consent. If any network connection is used, it must be by default cryptographically secured against MITM attacks.
Bohužel takových šmejďáren je dneska plno.
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.