4 ms·
"More often, attackers want signing keys so they can sign their own binaries" Isn't the idea that you don't have trust signing keys anymore because you rely on
by shipstern 6y ago
"More often, attackers want signing keys so they can sign their own binaries"
Isn't the idea that you don't have trust signing keys anymore because you rely on consensus? An attacker would probably have a much harder time compromising 10 vendors instead of one.
You are right, about complexity and issues, and you certainly don't "need" reproducible builds, depending on what you are after but it can be beneficial.
Also, you're arguments often seem to come out of thin air:
"reproducible builds are not for users" Why? Maybe not for the average user (yet).