Hacker News new | past | comments | ask | show | jobs | submit login

The arguments "don't follow." Reproducible builds were indeed more than once used to verify that the published binary does correspond to the published source.

Without having them, that kind of verification is much harder, depending on the build setup used, it can be even too hard to be achieved at all.

So we do have clear advantages of having the build infrastructure which results in reproducible builds, and I don't see anything that can substitute that.

The argument "if you build yourself from the sources, your build is then trusted" is not reflecting the reality. Most of the users are never going to build from the sources. Having reproducible builds, only a few people have to build from the sources to verify the binaries for the vast majority. Not to mention that without reproducibility, you can't even know if your own build environment is misconfigured.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: