4 ms·
Maybe im missing something but it seems the justification behind this is based on a situation in which source wasnt open. Debian is open so why is reproducibili
by hmmm___food 9y ago
Maybe im missing something but it seems the justification behind this is based on a situation in which source wasnt open. Debian is open so why is reproducibility a priority?
- kalmi10 9y agoSo that anyone can check whether a binary (on the mirrors) has been tampered with in ways that are not present in the source.
- yakubin 9y agoOn the contrary. Reproducibility means that given the source you are able to produce the exact same binary, i.e. you can verify that someone didn't modify it before building. When software isn't open, then reproducibility is meaningless, because you don't have the source, so: 1. you can't verify anything (you can't compile anything); 2. assurance of the binary not being modified gives you nothing, since you don't know if there is no malicious code in the original source code.
- thechao 9y agoI know Debian has lofty goals with respect to reproducibility, but on a purely "I hate waiting for builds", getting deterministic object files can prevent spurious linking. For example: change a comment, watch your code link for 10 minutes.
- lamby 9y agoMmm. Think of the CO2/power savings at a big coding shop like, I dunno, Google...
- wiz21c 9y agoJust to give an example, think about some software you put in a voting machine. Even if the code is open source and given to voters, they need to be able to compile it themselves and compare their compiled version to the one in the voting machine... (well, to be honest, this only makes sense if the voting machine runs the compiled code only and doesn't sneak other stuff in at runtime, but that's another story)
- AdmiralAsshat 9y agoNot always. TrueCrypt was open source, and yet a huge number of people were worried that the distributed binaries could be backdoor-ed in some way. See this article about someone trying to create a reproducible binary of TrueCrypt.[0] [0]https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binaries-analysis/ https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...
- bluGill 9y agoReflections on trusting trust. http://dl.acm.org/citation.cfm?id=358210 http://dl.acm.org/citation.cfm?id=358210 The paper is a classic in computer science so you should know it.
- stordoff 9y agoDebian being open only gives you any sort of assurance if you can prove the binary you are using is compiled from that source. Without reproducible builds, you can only (easily) do that if you are building the source yourself (which obviously most people don't). Reproducibility doesn't really make much sense when the code _isn't_ open - knowing that unknown source code can reliably produce the same output isn't that valuable.