Skip to content Skip to footer

5 Comments

  • Post Author
    imcritic
    Posted March 26, 2025 at 5:36 pm

    I don't get how someone achieves reproducibility of builds: what about files metadata like creation/modification timestamps? Do they forge them? Or are these data treated as not important enough (like it 2 files with different metadata but identical contents should have the same checksum when hashed)?

  • Post Author
    c0l0
    Posted March 26, 2025 at 5:43 pm

    I never really understood the hype around reproducible builds. It seems to mostly be a vehicle to enable tivoization[0] while keeping users sufficiently calm. With reproducible buiilds, a vendor can prove to users that they did build $binary from $someopensourceproject, and then digitally sign the result so that it – and only it – would load and execute on the vendor-provided and/or vendor-controlled platform. But that still kills effective software freedom as long as I, the user, cannot do the same thing with my own build (whether it is unmodified or not) of $someopensourceproject.

    Therefore, I side with Tavis Ormandy on this debate: https://web.archive.org/web/20210616083816/https://blog.cmpx…

    [0]: https://en.wikipedia.org/wiki/Tivoization

  • Post Author
    geocrasher
    Posted March 26, 2025 at 5:58 pm

    What is the significance of a reproducible build, and how is it different than a normal distribution?

  • Post Author
    zozbot234
    Posted March 26, 2025 at 6:12 pm

    Nice, these live images could become the foundation for a Debian-based "immutable OS" workflow.

  • Post Author
    abdullahkhalids
    Posted March 26, 2025 at 6:22 pm

    Is the build infrastructure for Debian also reproducible? It seems like we if someone wants to inject malware in Debian package binaries (without injecting them into the source), they have to target the build infrastructure (compilers, linkers and whatever wrapper code is written around them).

    Also, is someone else also compiling these images, so we have evidence that the Debian compiling servers were not compromised?

Leave a comment

In the Shadows of Innovation”

© 2025 HackTech.info. All Rights Reserved.

Sign Up to Our Newsletter

Be the first to know the latest updates

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.