3 ms·
> You can already verify that a > toolchain wasn't backdoored ) > today How, exactly? If we both compiled hello.c (a prototypical hello world program), and e
by wildfire 5y ago
> You can already verify that a
> toolchain wasn't backdoored )
> today
How, exactly?
If we both compiled hello.c (a prototypical hello world program), and exchanged binaries; how would you verify my build wasn't malicious?
- taviso 5y agoI think the workflow you're proposing is to take some trusted source code, then compile it to make a trusted binary. Now compare the trusted binary to the untrusted binary provided by the vendor - If they're the same - then it must have been made by an uncompromised toolchain. That does require reproducible builds, but here is how to do it without reproducible builds: Take the trusted source code, then compile it to make a trusted binary. Now put the untrusted binary in the trash, cause you already have a trusted binary :)
- squiggleblaz 5y agoHow about if the system will only run signed builds? Couldn't you use it to verify the signed build by stripping the signature and comparing them?