The Following 5 Users Say Thank You to juiceme For This Useful Post: | ||
![]() |
2018-05-05
, 22:06
|
|
Posts: 6,450 |
Thanked: 20,983 times |
Joined on Sep 2012
@ UK
|
#52
|
![]() |
2018-05-06
, 04:30
|
Posts: 1,296 |
Thanked: 4,321 times |
Joined on Oct 2014
|
#53
|
![]() |
2018-05-06
, 05:10
|
|
Posts: 6,450 |
Thanked: 20,983 times |
Joined on Sep 2012
@ UK
|
#54
|
The Following 4 Users Say Thank You to pichlo For This Useful Post: | ||
![]() |
2018-05-06
, 05:20
|
|
Posts: 6,450 |
Thanked: 20,983 times |
Joined on Sep 2012
@ UK
|
#55
|
![]() |
2018-05-06
, 05:22
|
Posts: 1,296 |
Thanked: 4,321 times |
Joined on Oct 2014
|
#56
|
Sorry but that's just silly. For at least two reasons:
1) A checksum match can only guarantee that the compiled binary matches the supplied sources. Not that the sources are safe and do not contain some hidden gems.
2) A checksum is not going to match anyway. At least in my experience, every time I build something I get a slightly different binary. The compiler embeds things like the build date/time etc.
The Following 5 Users Say Thank You to nieldk For This Useful Post: | ||
![]() |
2018-05-06
, 06:59
|
Community Council |
Posts: 4,920 |
Thanked: 12,867 times |
Joined on May 2012
@ Southerrn Finland
|
#57
|
The Following 5 Users Say Thank You to juiceme For This Useful Post: | ||
![]() |
2018-05-06
, 07:21
|
Posts: 84 |
Thanked: 267 times |
Joined on Apr 2016
|
#58
|
The Following 4 Users Say Thank You to feedme For This Useful Post: | ||
![]() |
2018-05-06
, 08:09
|
Posts: 74 |
Thanked: 355 times |
Joined on Aug 2017
|
#59
|
The Following 4 Users Say Thank You to jenix For This Useful Post: | ||
![]() |
2018-05-06
, 09:27
|
|
Posts: 6,450 |
Thanked: 20,983 times |
Joined on Sep 2012
@ UK
|
#60
|
In most cases the possibility of reproducible build from sources already deters the will to put in backdoors.
The Following 4 Users Say Thank You to pichlo For This Useful Post: | ||
If you read it again you will notice I said Binary distribution can be allowed if the sources are available and mechanism for reproducible build verification exists.
This means that somebody can build the sources and verify the resulting RPM is what is ptovided!!!