Post #2760395
2026-05-13 19:00 UTC
@dangoodin@infosec.exchange it would not have caught the xz attack. But is the point of reproducible builds more about consistency and reliability than security?
Replies (2)
-
@brown@infosec.exchange 2026-05-13 19:33
@kemotep@mastodo.neoliber.al @dangoodin@infosec.exchange it’s about being able to prove that the binary distribution matches the source code. If the source code is already tainted it won’t help.
-
@GeorgWeissenbacher@fediscience.org 2026-05-13 19:43
@kemotep@mastodo.neoliber.al @dangoodin@infosec.exchange well, in the xz case, it was actually one of the main contributors who slipped in the attack. There is little that can be done against that.