[Hamara-devel] reproducible builds for hamara ?

shirish shirish at hamaralinux.org
Mon May 4 19:30:07 BST 2015


Hi all,
Both Debian and Fedora have doing reproducible builds for the entire 
archive.

See https://lists.debian.org/debian-devel-announce/2015/02/msg00007.html 
for some info. and a range of links which share more about how to go 
about it and what's it all about.

This is about fedora 
http://securityblog.redhat.com/2013/09/18/reproducible-builds-for-fedora/

This is very much in-tune with the recent post on TheIntercept

https://firstlook.org/theintercept/2015/03/10/ispy-cia-campaign-steal-apples-secrets/

and the document detailing the same.

https://firstlook.org/theintercept/document/2015/03/10/strawhorse-attacking-macos-ios-software-development-kit/

You can find a bit of history as well at :-

https://blog.torproject.org/blog/deterministic-builds-part-one-cyberwar-and-global-compromise

https://blog.torproject.org/blog/deterministic-builds-part-two-technical-details

I do hope to blog about it with some simple examples on the coming 
week-end and hopefully also simplify the concept itself so its easier 
for a lay person to understand.

Would be looking forward to comments from the team, is this on our 
roadmap or should we wait for sometime to have some more understanding 
of the same + limitations.

-- 
Regards,
Shirish Agarwal,
Community Lead,
Hamaralinux.org


More information about the Hamara-devel mailing list