logoalt Hacker News

murderfstoday at 7:51 AM3 repliesview on HN

Has there been a single publicly known attack that would have been prevented by this?


Replies

MomsAVoxelltoday at 11:13 AM

Why should it only be valuable if the effects were to be publicly known?

There are plenty of places in industrial computing where reproducible builds have prevented subterfuge within the organizations themselves. Injecting binaries to do inf-/exfiltration is a long-standing industrial espionage activity which is of immense value to all users of the operating system - not just the consumer users.

show 1 reply
PunchyHamstertoday at 10:13 AM

Zero in Debian. They have enough other procedures to catch it.

Less diligent projects had it but there are easier ways to fix it

LtWorftoday at 9:44 AM

Several actually. Pypi is regularly targeted in this way.

show 2 replies