-
@taviso @halvarflake @fugueish @alexstamos @sleevi_ @durumcrustulum @LeaKissner We might have to agree to disagree here. Writing a targeted backdoor for a specific user group and/or shipping a tampered binary to that specific group seems significantly easier to me than writing an innocent-looking bug in the global, published code base. Of course there are
-
@taviso @halvarflake @fugueish @alexstamos @sleevi_ @durumcrustulum @LeaKissner combinations of other approaches (code signing, transparency logs, paid-for auditors with public reports, etc.) that can mitigate some of these vectors. But if you can do reproducible builds for open source releases with co-signing by independent build servers, why would you not?