| ▲ | charcircuit 2 days ago | ||||||||||||||||
Reproducible builds and bootstrapping doesn't stop physical extortion of shipping a new compromised version either. | |||||||||||||||||
| ▲ | lrvick a day ago | parent [-] | ||||||||||||||||
Sure it does, if you deterministically full source bootstrap, build, and sign the same image m-of-n places with different hardware owned by different people, all of whom only sign if everyone gets identical results, and this can be easily verified with remote attestation at runtime on a running server. This is not a fantasy. This is exactly how https://caution.co works. We can cryptographically attest with high confidence what code is running on a remote server at any given moment with these tactics. Entire classes of attacks are taken off the table with this approach, including BGP attacks if deployed properly. | |||||||||||||||||
| |||||||||||||||||