Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, I did not say those things. That aside, if you wanted to, after an audit/review concluded, could you put a backdoor in your software? Since it's closed source, would anyone know about it?


If there's a deterministic build process, in theory, the auditor would know something was up if the binary differed.


In deterministic build? It will be very hard. I doubt that any audit signs on anything other than specific versions.


does microsoft use deterministic builds?


There are these things called signed binaries...


But signing binaries does not prove from which source the binaries have been build, only who did it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: