LWN: Comments on "Security software verifiability" https://lwn.net/Articles/564263/ This is a special feed containing comments posted to the individual LWN article titled "Security software verifiability". en-us Sun, 26 Oct 2025 13:39:57 +0000 Sun, 26 Oct 2025 13:39:57 +0000 https://www.rssboard.org/rss-specification lwn@lwn.net Security software verifiability https://lwn.net/Articles/564705/ https://lwn.net/Articles/564705/ deepfire <div class="FormattedComment"> Gitian, as suggested above, is, AIUI, a better choice, as it allows cross-verification by independent parties.<br> </div> Sat, 24 Aug 2013 12:14:54 +0000 Security software verifiability https://lwn.net/Articles/564698/ https://lwn.net/Articles/564698/ jospoortvliet <div class="FormattedComment"> Would building binaries on a public service like an openbuildservice.org not be a huge help in determining if binaries are build from the source they are supposed to be build from? With OBS and its ability to repeatedly build exactly the same thing you could repeat a build and md5sum the resulting binaries, compare to what you've got installed...<br> <p> You could even run a local OBS instance (build from the code yourself, if you like) and repeat builds done on the public one if you don't trust it...<br> </div> Sat, 24 Aug 2013 08:49:32 +0000 Security software verifiability https://lwn.net/Articles/564631/ https://lwn.net/Articles/564631/ zooko <div class="FormattedComment"> I just posted a follow-up on the cryptography@randombit.net list:<br> <p> <a href="http://lists.randombit.net/pipermail/cryptography/2013-August/005095.html">http://lists.randombit.net/pipermail/cryptography/2013-Au...</a><br> </div> Fri, 23 Aug 2013 15:24:11 +0000 Security software verifiability https://lwn.net/Articles/564619/ https://lwn.net/Articles/564619/ zooko <div class="FormattedComment"> It's not clear to me about the availability and licensing of Silent Circle's code. They have several different products, and I can't tell if the current binary releases distributed through the phone app stores correspond to any of the source code that has been posted. I rather doubt it, as the source code hasn't been updated in at least 5 months: <a href="https://github.com/SilentCircle">https://github.com/SilentCircle</a><br> <p> Also I haven't seen a licensing declaration about how we are allowed to use the source code.<br> </div> Fri, 23 Aug 2013 14:36:55 +0000 Security software verifiability https://lwn.net/Articles/564618/ https://lwn.net/Articles/564618/ zooko <div class="FormattedComment"> Bitcoin uses gitian now: <a href="https://en.bitcoin.it/wiki/Release_process">https://en.bitcoin.it/wiki/Release_process</a><br> </div> Fri, 23 Aug 2013 14:33:44 +0000 Security software verifiability https://lwn.net/Articles/564367/ https://lwn.net/Articles/564367/ pj <div class="FormattedComment"> I believe gitian (<a href="http://gitian.org/">http://gitian.org/</a>) is a workable solution to this; multiple builders mean it's difficult to compromise *all* of them.<br> </div> Thu, 22 Aug 2013 13:20:33 +0000