99 points by naves 6 hours ago | 6 comments
kpcyrd 46 minutes ago
> Even when source is available, as in open source operating systems like Linux, approximately no one checks that the distributed binaries match the source code.

This was not the case in 2023 for Arch Linux[1] back when the post was originally published, and is also not the case for Debian[2] since 2024.

[1]: https://reproducible.archlinux.org/

[2]: https://reproduce.debian.net/

EvanAnderson 5 hours ago
(2023)

Discussion at the time: https://news.ycombinator.com/item?id=38020792

Y_Y 1 hour ago
Would be fun to see if an llm could produce this (assuming tfa and other solutions weren't present in the training data).
riemannzeta 2 hours ago
Reflections on Trusting "Reflections on Trusting Trust"?
2 hours ago
kitsume2016 3 hours ago
[flagged]