toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

378
active users

#reproduciblebuilds

1 post1 participant1 post today
Ian Brown 👨🏻‍💻<p>In fact, governments probably should only EVER deploy executables they have built themselves, using their own compilers (see the classic computer science paper Reflections on Trusting Trust). </p><p>You’d also need chip <a href="https://eupolicy.social/tags/microcode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>microcode</span></a> auditing and verification for security-critical systems. And some level of chip assurance. And 🇬🇧 Cell-like audits… Details to be determined 😉</p><p><a href="https://eupolicy.social/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a><br> <a href="https://eupolicy.social/tags/StrategicAutonomy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StrategicAutonomy</span></a> <a href="https://eupolicy.social/tags/audit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>audit</span></a> <a href="https://eupolicy.social/tags/escrow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>escrow</span></a></p>
IzzyOnDroid ✅<p>You're interested in Reproducible Builds for Android apps? We've just updated our Wiki on those:</p><p><a href="https://gitlab.com/IzzyOnDroid/repo/-/wikis/Reproducible-Builds/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gitlab.com/IzzyOnDroid/repo/-/</span><span class="invisible">wikis/Reproducible-Builds/</span></a></p><p>There are new pages for setting up build recipes, and debugging/fixing RBs – which should help you when running your own builder. Which you btw can set up on your Linux machine within 5 minutes using the scripts provided at <a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a> :awesome:</p><p>Developers also find pages there on making/keeping their apps RB.</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://kolektiva.social/@licho" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>licho</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@osman" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>osman</span></a></span> provide evidence the code <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> released is actually being deployed.</p><ul><li>Whereas <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>monocles</span></a></span> has <a href="https://infosec.space/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a> to the point that <span class="h-card" translate="no"><a href="https://floss.social/@fdroidorg" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fdroidorg</span></a></span> literally pulls their <code>git</code> and builds it from source.</li></ul><p>Not to mention pushing a <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitcoin</span></a>-<a href="https://infosec.space/tags/Scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scam</span></a> (<a href="https://infosec.space/tags/MobileCoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MobileCoin</span></a>) disqualifies <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> per very design!<br><a href="https://www.youtube.com/watch?v=tJoO2uWrX1M" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=tJoO2uWrX1M</span><span class="invisible"></span></a></p><ul><li>Given the collection of <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PII</span></a> like <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumbers</span></a>, the ability to restrict functionality based off those and the fact that <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> is subject to <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a> make it inherently not trustworthy.</li></ul><p>And don't even get me started on the fact.it's not sustainable to run it as a <a href="https://infosec.space/tags/VCmoneyBurningParty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VCmoneyBurningParty</span></a>!</p><ul><li>As soon as Signal becomes a problem, it will be taken offline, and due to the fact that it is <a href="https://infosec.space/tags/centralized" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>centralized</span></a>, <a href="https://infosec.space/tags/proprietary" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>proprietary</span></a>, <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleVendor</span></a> &amp; <a href="https://infosec.space/tags/SingleProvider" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleProvider</span></a> that's trivial for authorities.</li></ul><p>Same as identifying users: They already got a <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumber</span></a> which in many juristictions one can't even obtain without <a href="https://infosec.space/tags/ID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ID</span></a> legally, thus making it super easy to i.e. find and locate a user. Even tze cheapest LEAs can force their local M(V)NOs to <a href="https://infosec.space/tags/SS7" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SS7</span></a> a specific number...</p><ul><li>All these are <em>unnecessary risks</em>, that could've been avoided, but explicitly don't even get remediated retroactively!</li></ul><p>Again: Signal has a <a href="https://infosec.space/tags/Honeypot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Honeypot</span></a> stench, and you better learn proper <a href="https://infosec.space/tags/E2EE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>E2EE</span></a>, <a href="https://infosec.space/tags/SelfCustody" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfCustody</span></a> and <a href="https://infosec.space/tags/TechLiteracy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechLiteracy</span></a> because <a href="https://web.archive.org/web/20210606070919/twitter.com/thegrugq/status/1085614812581715968" rel="nofollow noopener noreferrer" target="_blank"><em>corporations can't pull the 5th [Amendment] on your behalf</em>!</a></p>
LavX News<p>Enhancing Software Supply Chain Security: The Quest for Reproducible Releases</p><p>In an era where software supply chain security is paramount, developers are challenged to create reproducible releases. This article delves into the technical hurdles and innovative solutions that are...</p><p><a href="https://news.lavx.hu/article/enhancing-software-supply-chain-security-the-quest-for-reproducible-releases" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/enhancing</span><span class="invisible">-software-supply-chain-security-the-quest-for-reproducible-releases</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/SupplyChainSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChainSecurity</span></a> <a href="https://mastodon.cloud/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a> <a href="https://mastodon.cloud/tags/CI_CD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CI_CD</span></a></p>
jbz<p>"Over the last few releases, we changed our build infrastructure to make package builds reproducible. This is enough to reach 90%. The remaining issues need to be fixed in individual packages. After this Change, package builds are expected to be reproducible. Bugs will be filed against packages when an irreproducibility is detected. The goal is to have no fewer than 99% of package builds reproducible."</p><p><a href="https://www.phoronix.com/news/Fedora-43-Expect-Reproducible" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">phoronix.com/news/Fedora-43-Ex</span><span class="invisible">pect-Reproducible</span></a></p><p><a href="https://indieweb.social/tags/fedora" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fedora</span></a> <a href="https://indieweb.social/tags/reproduciblebuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproduciblebuilds</span></a> <a href="https://indieweb.social/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> <a href="https://indieweb.social/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a></p>
IzzyOnDroid ✅<p>With our rbuilder_setup scripts now ready, the wiki page on Verification Builders has been updated, too:</p><p><a href="https://gitlab.com/IzzyOnDroid/repo/-/wikis/Reproducible-Builds/Verification-Builder" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gitlab.com/IzzyOnDroid/repo/-/</span><span class="invisible">wikis/Reproducible-Builds/Verification-Builder</span></a></p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Wanted to run your own builder for <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> and were disappointed our RBuilder Setup was only available for Debian-based systems? Then we have good news for you: a few min ago, 2 PRs have been merged. The setup scripts now also support RPM &amp; Arch based systems 🥳</p><p>RPM/Arch lack packages for apksigner &amp; dexdiff (which are needed for debugging). We're on it, those will follow hopefully soon™.</p><p>Thanks to <span class="h-card" translate="no"><a href="https://mastodon.social/@Iamlooker" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Iamlooker</span></a></span> and Patrick (from FlorisBoard) for your help!</p><p><a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a></p>
IzzyOnDroid ✅<p>New day, new Milestone: now 500 apps at <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> are <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> :awesome:</p>
IzzyOnDroid ✅<p>🐣 oops… the Easter egg hatched early! We've just reached a goal we hoped to achieve around Easter:</p><p>At <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> 40% – so 2 out of every 5 apps – are now <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> 🥳</p><p>So whenever you see one or more green shields next to the version of an app in our repo browser at <a href="https://apt.izzysoft.de/fdroid" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">apt.izzysoft.de/fdroid</span><span class="invisible"></span></a> you can be sure: this was built exactly from the source code it claims to be, nothing added or taken away.</p><p>Oh, and we should roll out those new shields soon™, so you see the independent builders 😉</p>
IzzyOnDroid ✅<p>Want to try running your own builder – to confirm apps as <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> or just to build your own apps? At <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> we've just made "easy setup scripts" available which should take care for all requirements, while letting you choose which parts you want:</p><p><a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a></p><p>These scripts are not yet thoroughly tested (just a bit on Linux Mint/Debian/Ubuntu), so we'd welcome volunteers &amp; their feedback.</p><p>Thanks to <span class="h-card" translate="no"><a href="https://social.nlnet.nl/@nlnet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nlnet</span></a></span> for supporting us on this project! You're awesome :awesome:</p>
IzzyOnDroid ✅<p>Welcome to the RB family, Payload Dumper 🥳</p><p><a href="https://apt.izzysoft.de/packages/com.rajmani7584.payloaddumper" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/com.r</span><span class="invisible">ajmani7584.payloaddumper</span></a></p><p>Payload Dumper lets you extract boot.img or any other (partition) images without any PC and without SuperUser (root) access, directly on your Android device.</p><p>Thanks to the help of its developer, with today's release this app is now RB :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, Street­Measure 🥳</p><p><a href="https://apt.izzysoft.de/packages/de.westnordost.streetmeasure" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/de.we</span><span class="invisible">stnordost.streetmeasure</span></a></p><p>StreetMeasure is an app to measure distances and heights. It was made for usage with StreetComplete and other OpenStreetMap editors. But you can use it for other things, too.</p><p>Thanks to the joint efforts with its author (thanks Tobias!), starting with v1.5 this app is now RB :awesome:</p><p>RB status at IoD now: 471 apps (38.4%)</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
LavX News<p>Reproducible Builds: A Milestone for openSUSE's RBOS Project Enhancing Supply Chain Security</p><p>The Reproducible-openSUSE (RBOS) project has achieved a significant milestone by demonstrating the ability to build a Linux distribution with 100% bit-identical packages. This advancement is crucial f...</p><p><a href="https://news.lavx.hu/article/reproducible-builds-a-milestone-for-opensuse-s-rbos-project-enhancing-supply-chain-security" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/reproduci</span><span class="invisible">ble-builds-a-milestone-for-opensuse-s-rbos-project-enhancing-supply-chain-security</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/SupplyChainSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChainSecurity</span></a> <a href="https://mastodon.cloud/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a> <a href="https://mastodon.cloud/tags/openSUSE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openSUSE</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.ie/@davey_cakes" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>davey_cakes</span></a></span> personally, I'd point at <a href="https://infosec.space/tags/Codium" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Codium</span></a> which removes all the <a href="https://infosec.space/tags/proprietary" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>proprietary</span></a> <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> <a href="https://infosec.space/tags/bloat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bloat</span></a> and instead has <a href="https://infosec.space/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a>.</p><p><a href="https://vscodium.com" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">vscodium.com</span><span class="invisible"></span></a></p>
IzzyOnDroid ✅<p>Miss the <a href="https://floss.social/tags/AndroidAppRain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AndroidAppRain</span></a> at <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> ? Well, I'm currently busy filling the gaps with <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> – and as I was asked: Yes, that's much harder the longer an app was not updated. Missing dependencies that cannot be fixed anymore (like, JCenter went offline last year). Build issues / upstream fixes needed, but the dev no longer around to help. And so on. So with 3+ years unmaintained, maybe 9 our of 10 apps simply fail…</p><p>Doing our best to get as much in as possible, though 🤞</p>
Vagrant Cascadian<p>Note to self:</p><p>I must admit I probably could have used a slide about why <a href="https://floss.social/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a> is important in my talk yesterday.</p><p>More and more I would like to stress that reproducible builds are most importantly about being able to say that a given artifact was produced from specific bit of source code, and all of the security and other benefits derive directly or indirectly from that.</p><p>Ideally you can recursively make such assertions all the way down, and you end up with <a href="https://floss.social/tags/BootstrappableBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BootstrappableBuilds</span></a></p>
Vagrant Cascadian<p>Speaking on the half-hour at <span class="h-card" translate="no"><a href="https://fosstodon.org/@pycascades" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>pycascades</span></a></span> </p><p>My first go presenting "Re-Py-Ducible Builds" </p><p>So refreshing to be at a conference where everyone is wearing a mask!</p><p><a href="https://floss.social/tags/WearAMask" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WearAMask</span></a> <a href="https://floss.social/tags/PyCascades2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PyCascades2025</span></a> <a href="https://floss.social/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a> <a href="https://floss.social/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, Hypatia 🥳 </p><p><a href="https://apt.izzysoft.de/packages/org.maintainteam.hypatia" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/org.m</span><span class="invisible">aintainteam.hypatia</span></a></p><p>Hypatia is the worlds first FOSS malware scanner for Android. It is powered by ClamAV style signature databases.</p><p>Thanks to some help by <span class="h-card" translate="no"><a href="https://mastodon.social/@asandikci" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>asandikci</span></a></span> from the MaintainTeam we managed to the the green shield up today :awesome: </p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://possum.city/@tauon" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tauon</span></a></span> </p><p>1) <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a> is just <a href="https://infosec.space/tags/CyberFacism" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberFacism</span></a>, look it up!<br><a href="https://en.wikipedia.org/wiki/CLOUD_Act" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">en.wikipedia.org/wiki/CLOUD_Act</span><span class="invisible"></span></a></p><ul><li>And with <a href="https://infosec.space/tags/Trumpism" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trumpism</span></a> ravaging the <a href="https://infosec.space/tags/USA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>USA</span></a> must be considered as <a href="https://infosec.space/tags/hostile" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hostile</span></a> as <a href="https://infosec.space/tags/Russia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Russia</span></a> and the <em>"P.R."</em> <a href="https://infosec.space/tags/China" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>China</span></a> by anyone who takes <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpSec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> &amp; <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ComSec</span></a> seriously!</li></ul><p>-</p><p>2) <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> 's <a href="https://infosec.space/tags/Server" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Server</span></a> code is proprietary and since it's centralized we can't trust that the code they release is what's running on their backend! </p><ul><li>Plus their <a href="https://infosec.space/tags/App" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>App</span></a> doesn't allow <a href="https://infosec.space/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a> (if Signal was <a href="https://infosec.space/tags/FLOSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FLOSS</span></a> it would be on <span class="h-card" translate="no"><a href="https://floss.social/@fdroidorg" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fdroidorg</span></a></span> / <a href="https://infosec.space/tags/Fdroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fdroid</span></a>) but alas it isn't!</li></ul><p>-</p><p>3) <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> still demands <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumbers</span></a> which are <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PII</span></a> either by association (<a href="https://infosec.space/tags/Number" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Number</span></a> =&gt; <a href="https://infosec.space/tags/ICCID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ICCID</span></a> = <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SIM</span></a> = <a href="https://infosec.space/tags/IMSI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IMSI</span></a> =&gt; <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IMEI</span></a> =&gt; Location Data <a href="https://infosec.space/@kkarhan/113467346741876822" rel="nofollow noopener noreferrer" target="_blank">as I explained before</a><a href="https://infosec.space/@kkarhan/113878565911126519" rel="nofollow noopener noreferrer" target="_blank">twice</a>) or mandatory <a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KYC</span></a> / <a href="https://infosec.space/tags/ID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ID</span></a> requirements (even on prepaid cards), which an increasing amount of juristictions <em>do</em>...</p><ul><li>They have no <em>"<a href="https://infosec.space/tags/LegitimateInterest" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LegitimateInterest</span></a>"</em> demanding said <a href="https://infosec.space/tags/PersonallyIdentifyingInformation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PersonallyIdentifyingInformation</span></a> to begin with! </li></ul><p>-</p><p>But don't take my word for it.<br><a href="https://www.youtube.com/watch?v=tJoO2uWrX1M" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=tJoO2uWrX1M</span><span class="invisible"></span></a></p><ul><li>Ask yourself if you'd trust someone <a href="https://www.youtube.com/watch?v=0DSGq9FQKU4" rel="nofollow noopener noreferrer" target="_blank">peddlibg</a> <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitcoin</span></a> <a href="https://infosec.space/tags/Scams" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scams</span></a> like <a href="https://infosec.space/tags/MobileCoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MobileCoin</span></a> with your data!</li></ul>
Stefano Zacchiroli<p>Last but not least, my student <span class="h-card" translate="no"><a href="https://chaos.social/@luj" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>luj</span></a></span> will present «How reproducible is <a href="https://mastodon.xyz/tags/NixOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NixOS</span></a>?» on Saturday <a href="https://fosdem.org/2025/schedule/event/fosdem-2025-4430-how-reproducible-is-nixos-/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">fosdem.org/2025/schedule/event</span><span class="invisible">/fosdem-2025-4430-how-reproducible-is-nixos-/</span></a> . The talk is about our large-scale historical (2017-2023) experiments on the bitwise reproducibility of <a href="https://mastodon.xyz/tags/Nix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Nix</span></a> packages. Unmissable if you are into functional package managers and/or <a href="https://mastodon.xyz/tags/reproduciblebuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproduciblebuilds</span></a> .</p><p>For the gory details, check out the preprint of our <a href="https://mastodon.xyz/tags/MSR2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MSR2025</span></a> paper about this work: <a href="https://upsilon.cc/~zack/research/publications/msr-2025-nix-reproducibility.pdf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">upsilon.cc/~zack/research/publ</span><span class="invisible">ications/msr-2025-nix-reproducibility.pdf</span></a></p><p><a href="https://mastodon.xyz/tags/FOSDEM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FOSDEM</span></a></p>