Gave a talk at #FOSSY yesterday about #ReproducibleBuilds and #BootstrappableBuilds and how close we are to actually counter the infamous #TrustingTrust attack.
The slides are packaged as a Debian package, including a signed .buildinfo file, so you should be able to recreate my slides bit-for-bit identically!
https://www.aikidev.net/~vagrant/talks/2023/fossy/
However, my actual talk included a fair amount of non-determinism, thanks for all the great questions!
https://2023.fossy.us/schedule/presentation/118/
Videos should be available soon!
Breaking the Chains of Trusting Trust video now available:
https://archive.org/details/fossy2023_Breaking_the_Chains_of_Trustin
#FOSSY #FOSSY2023 #ReproducibleBuilds #BootstrappableBuilds #TrustingTrust
@vagrantc > However, my actual talk included a fair amount of non-determinism, thanks for all the great questions!
next step: reproducible talk :D
Not sure I would want reproducible talks, even without reproducibility, they can sometimes feel a bit repetative...
Some things are best with more variety! :)
@vagrantc @reproducible_builds
Amazing talk, fun and very informative. Highly recommended!
@vagrantc next stop secure hardware!