GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Janneke (janneke@todon.nl)'s status on Wednesday, 04-Oct-2023 07:10:46 JSTJannekeJanneke
    in reply to
    • Vagrant Cascadian
    • Alfred M. Szmidt

    @amszmidt
    That's right, they do not help: they're essential!

    Without Reproducible builds and Bootstrappable builds, free software, and certainly software freedom, is an illusion at best.

    Re: Trusting Trust, see for example the excellent talk by @vagrantc

    https://archive.org/details/fossy2023_Breaking_the_Chains_of_Trustin

    #RebproducibleBuilds
    #Bootstrappable
    #BootstrappableBuilds

    In conversationWednesday, 04-Oct-2023 07:10:46 JST from todon.nlpermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      best.re - このウェブサイトは販売用です! - best リソースおよび情報
      このウェブサイトは販売用です! best.re は、あなたがお探しの情報の全ての最新かつ最適なソースです。一般トピックからここから検索できる内容は、best.reが全てとなります。あなたがお探しの内容が見つかることを願っています!
    2. Domain not in remote thumbnail source whitelist: ia600505.us.archive.org
      Breaking the Chains of Trusting Trust: Reproducible Builds and More! by Vagrant Cascadian
      Corrupted build environments can deliver compromised cryptographically signed binaries. Several exploits in in critical supply chains have been demonstrated in recent years, proving that this is not just theoretical. The most well secured build environments are still single points of failure when they fail. In 1984, Ken Thompson presented "Reflections on trusting trust" which described an attack on a build toolchain that would be impossible to detect through source code review ... in the decades since, what has been done to actually mitigate these types of attacks? Work in the Reproducible Builds and Bootstrappable Builds communities has been progressing steadily in recent years, and can be used to significantly reduce the risks of "Trusting Trust" and other supply chain attacks, by making it possible to independently review not only the end result, but the entire toolchain used to build a given artifact. This talk will focus on the state of the art from several angles in related Free and Open Source Software projects, what works, current challenges and future plans for building trustworthy toolchains you do not need to trust. https://reproducible-builds.org https://bootstrappable.orgSpeaker: Vagrant Cascadian
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.