4 ms·
> For example, SolarWinds now conducts a two-way build. The code is pulled from source code control, built, hashed, then decompiled and compared back to the ori
by ENOTTY 6y ago
> For example, SolarWinds now conducts a two-way build. The code is pulled from source code control, built, hashed, then decompiled and compared back to the original, to ensure what ships is what was coded and nothing more or less.
This seems like a high-labor and error-prone way to detect a possible integrity compromise of your build infrastructure. Maybe they've done this, but what software shops need to do is better control the integrity of their build infrastructure and the confidentiality of their code signing keys.
Ideally, build infrastructure would be immutable (resistant to unauthorized change), burnable (defeats persistence), and auditable (changes need to authorized and logged). The build infrastructure itself would produce auditable artifacts from the build, including hashes of input files, compilers, etc.
- richij 6y ago#include ~/memes/why-not-both.gif