Reply To: antiX-25-full-beta1 for public testing

Forum › Forums › News › Announcements › antiX-25-full-beta1 for public testing › Reply To: antiX-25-full-beta1 for public testing

#191654
andyprough
Member

    broadcom-sta-dkms is non-free.
    Broadcom is a major US corporation.
    Suppose there would be the intention to induce surveillance technology into open source – how could that be done?
    Should not any proprietary kernel modification be suspicious?

    See: https://www.debian.org/security/faq#contrib

    Q: How is security handled for contrib, non-free and non-free-firmware?

    A: The short answer is: it’s not. Contrib, non-free and non-free-firmware aren’t official parts of the Debian Distribution and are not released, and thus not supported by the security team. Some non-free packages are distributed without source or without a license allowing the distribution of modified versions. In those cases no security fixes can be made at all. If it is possible to fix the problem, and the package maintainer or someone else provides correct updated packages, then the security team will generally process them and release an advisory.

    Not only that, from what I can read of the Debian changelog for broadcom-sta-dkms, it doesn’t appear that Broadcom has bothered to update the underlying broadcom-sta package from version # 6.30.223.271 since October 5, 2015.
    https://metadata.ftp-master.debian.org/changelogs//non-free/b/broadcom-sta/broadcom-sta_6.30.223.271-17_changelog

    That’s over 10 years now, with no apparent security updates whatsoever, just various patches by the Debian maintainers to make the driver work with different kernel versions. For networking firmware that’s a complete proprietary black box as far as I can tell. /usr/src/broadcom-sta-6.30.223.271/lib/wlc_hybrid.o_amd64 is a 7.0mb “object code” file that can’t be opened in any text editor that I’ve tried.

    Correct me if I’m wrong on any of the above.