Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You're focusing on the wrong issue. Just because reproducible builds don't solve all avenues of attack doesn't mean they're worthless. No, a reproducible build does not give you any confidence about the quality of the source. It gives you confidence that you're actually looking at the correct source when your build hash matches the published hash, nothing more.

A window that can be smashed in is still a vulnerability, so there is no value in people locking their front doors.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: