<pie___>
wonder if we could/should do something like SSL Observatory but for build reproductions
<pie___>
(basically a database of input - output hashes?)
<andi->
What would that serve us? We have r13y.com that is alreayd a step in that direction. What that would be is basically a database that takes all the narinfo files and puts them in a database?
<ekleog>
if we have a third “input-output correspondance signature” field (and maybe a fourth “signer” field) it'd make something really useful IMO
<ekleog>
for the “distrust hydra” long-term objective
<ekleog>
now, it's not at all a priority IMO
<pie___>
dunno how to prevent malicious spam tho
<ekleog>
not sure spam would be a big issue, with no amplification factor
<pie___>
how do you differentiate valid and invalid data
<pie___>
ok thats kind of orthogonal
<ekleog>
yup
<ekleog>
one will be assumed to trust only known signers
<ekleog>
if someone downloads the data and trusts everyone, it's their problem
<pie___>
i figured something somethign web of trust but does that really work
pie___ has quit [Ping timeout: 272 seconds]
justanotheruser has quit [Ping timeout: 272 seconds]
pie_ has joined #nixos-security
justanotheruser has joined #nixos-security
justanotheruser is now known as Mr_Notheruser
Mr_Notheruser has quit [Ping timeout: 252 seconds]
justanotheruser has joined #nixos-security
<Foxboron>
pie__: My master thesis is about publishing rebuild submission of debian packages on a transparency log
<Foxboron>
ekleogs approach is a bit similar to what we discussed at the reproducible builds summit regarding trusting rebuilders. Leave trust up to the user, but distribute a initial list.
<pie_>
Foxboron, oh huh sounds hard
<pie_>
is the thesis done yet?
<Foxboron>
Delivery on saturday :p
<pie_>
good luck \o/ :D
<Foxboron>
thanks! Interesting topic :)
<Foxboron>
Going to be playing a lot with these concepts in relation to Arch Linux when i'm done with this
justanotheruser has quit [Read error: Connection reset by peer]
Synthetica has quit [Quit: Connection closed for inactivity]