←back to thread

766 points bertman | 1 comments | | HN request time: 0.209s | source
Show context
abdullahkhalids ◴[] No.43485194[source]
Is the build infrastructure for Debian also reproducible? It seems like we if someone wants to inject malware in Debian package binaries (without injecting them into the source), they have to target the build infrastructure (compilers, linkers and whatever wrapper code is written around them).

Also, is someone else also compiling these images, so we have evidence that the Debian compiling servers were not compromised?

replies(5): >>43485310 #>>43485572 #>>43485619 #>>43486186 #>>43492801 #
layer8 ◴[] No.43485619[source]
And what about the hardware on which the build runs? Is it reproducible? ;)
replies(5): >>43486069 #>>43486115 #>>43486158 #>>43486241 #>>43488837 #
1. kragen ◴[] No.43486115[source]
Working on it! But in general the answer is that for most purposes it's good enough to show that many independently produced pieces of hardware can reproduce the same results.