Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

50% Positive

Analyzed from 99 words in the discussion.

Trending Topics

#already#independently#verifier#should#while#service#file#reproduced#name#trusted

Discussion (1 Comments)Read Original on HackerNews

edelbitter•30 minutes ago
> this file was independently reproduced by <name of trusted party>

Sounds risky, unless paired with strong policy about what a verifier should do. e.g. if the verifier just grants network access to the buildbot that then checks what the result should look like, then compromise could remain invisible while the label silently downgrade to "independently downloaded by". And I do not expect there are many parties that would be willing to provide such service beyond their own needs, while simultaneously not already providing that service in places where the infrastructure and policies are already set (such as Debian). Or at least they would already contribute towards build dependencies that do not break reproducibility on every other version bump.