Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It’s entirely possible to inspect a binary even if the build isn’t reproducible.

https://news.ycombinator.com/item?id=41361609



"Entirely possible" is a misleading argument.

I don't understand why Signal is not pursuing the reproducible builds. It looks suspicious. Verification of a binary takes a huge effort and can only be done by knowledgeable people. Case in point: nobody noticed or cared about the lack of undisclosed binary updates of Signal without released sources.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: