3 ms·
If anything, a commercial security product that allows anyone to audit the source code seems like a pretty Useful Pattern
by xpaulbettsx 8y ago
If anything, a commercial security product that allows anyone to audit the source code seems like a pretty Useful Pattern
- dsr_ 8y ago...only if you can prove that the source code you show them builds the binary that you install, every single time.
- jgalt212 8y agoor you can compile it yourself, or am missing something from you comment?
- mattpavelle 8y agoRight. You could also compile it yourself with the same chainset / toolset the Krypton folks use and compare the binaries. There's probably a way to compare everything but the digital signature with two binaries too... Not sure
- dsr_ 8y agoThe overall concept is "reproducible builds". Without it, you have the Reflections on Trusting Trust problem.
- solatic 8y agoIf all rights are reserved on the original source code, then compiling the source code can be construed as intent for intellectual property theft, since the right to compile the code was never expressly given to you. Looking at all-rights-reserved code on a public repository on GitHub is like going to a strip club - you may look, but you can't touch.
- desdiv 8y agoThen it's a good thing that they made clarifications in their FAQ: >Feel free to compile Krypton from source and run it on your phone and workstation. [0] [0] https://krypt.co/faq/ https://krypt.co/faq/