Hacker News new | past | comments | ask | show | jobs | submit login

Read the client code? Bah! How do you know that's what's in the compiled binary?



Reproducible builds. This is pretty much exactly their purpose.


The non-facetious point here is that you have to root your trust in something (whether that's the maker of your reproducible build system, or your device, or your app, or the online service you use, or the chip foundry that made the CPU that runs your built-from-scratch-paranoid-OS).

It's better to have to trust somewhat verifiable promises about the Facebook app than to have to trust unverifiable promises about Facebook-the-entire-organization. That's the advantage that E2E provides.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: