4 ms·
Yes! The attack on SolarWinds Orion was an attack on its build process. A verified reproducible build would have detected the subversion, because the builds wou
by dwheeler 1y ago
Yes! The attack on SolarWinds Orion was an attack on its build process. A verified reproducible build would have detected the subversion, because the builds would not have matched (unless the attackers managed to detect and break into all the build processes).
- oneshtein 1y agoExact same binary can be hacked in exact same way on all platforms.
- yjftsjthsd-h 1y agoWhat?
- tomcam 1y agoIf I understand correctly that would require releasing the publisher’s private key, though,correct?
- dwheeler 1y agoOnly if you try to reproduce the signature. Usually the signature is stored separately. That way, the reproduced work's signature applies to it as well.
- dwheeler 1y agoThat would requiring breaking each of the separate build processes, which is very unlikely. This doesn't counter subverted source code, that's not what reproduciblrle builds are for.