I think it would be wise to add some sort of in-toto style verification that cryptographically checks proof that the reproducible builds were carried out and found equal. Without this piece, why would an attacker with insider access even bother to go through the reproducible builds process?
Thanks, Justin On Sat, Jan 30, 2021 at 7:15 PM David A. Wheeler < [email protected]> wrote: > My post "Preventing Supply Chain Attacks like SolarWinds” < > https://www.linuxfoundation.org/en/blog/preventing-supply-chain-attacks-like-solarwinds/> > prominently discusses verified reproducible builds. > > What would be especially helpful for accelerating deployment of verified > reproducible builds in a few key places? E.g., what tools, infrastructure, > people paid to do XYZ? > > Thanks! > > --- David A. Wheeler > >
