[Hamara-devel] reproducible builds for hamara ?
shirish
shirish at hamaralinux.org
Mon May 4 19:30:07 BST 2015
Hi all,
Both Debian and Fedora have doing reproducible builds for the entire
archive.
See https://lists.debian.org/debian-devel-announce/2015/02/msg00007.html
for some info. and a range of links which share more about how to go
about it and what's it all about.
This is about fedora
http://securityblog.redhat.com/2013/09/18/reproducible-builds-for-fedora/
This is very much in-tune with the recent post on TheIntercept
https://firstlook.org/theintercept/2015/03/10/ispy-cia-campaign-steal-apples-secrets/
and the document detailing the same.
https://firstlook.org/theintercept/document/2015/03/10/strawhorse-attacking-macos-ios-software-development-kit/
You can find a bit of history as well at :-
https://blog.torproject.org/blog/deterministic-builds-part-one-cyberwar-and-global-compromise
https://blog.torproject.org/blog/deterministic-builds-part-two-technical-details
I do hope to blog about it with some simple examples on the coming
week-end and hopefully also simplify the concept itself so its easier
for a lay person to understand.
Would be looking forward to comments from the team, is this on our
roadmap or should we wait for sometime to have some more understanding
of the same + limitations.
--
Regards,
Shirish Agarwal,
Community Lead,
Hamaralinux.org
More information about the Hamara-devel
mailing list