2 ms·
That doesn't protect you against a malicious developer.
by obscene 10y ago
That doesn't protect you against a malicious developer.
- jMyles 10y agoYou mean someone publishing source code and then falsely verifying the binary checksum? I mean, at the end of the day, it's very easy to verify - if the binary doesn't match what whomever gets when they compile, there better be a reason for it. Regardless, I don't think this is the biggest problem facing open source.
- Groxx 10y ago>if the binary doesn't match what whomever gets when they compile, there better be a reason for it. True, but deterministic compiles are stupendously difficult in most cases. Which is improving slowly, but still isn't usually an option.
- BuuQu9hu 10y agoDebian is up to 92% deterministic builds, so not that hard: https://tests.reproducible-builds.org/debian/reproducible.html https://tests.reproducible-builds.org/debian/reproducible.ht...
- Groxx 10y agoOoh, that is a heck of a lot better than the last time I looked at it. And a very neat link - thanks!