How 2 SpaceX Alums Are Using Encryption for Good
dcinno.streetwise.co
dcinno.streetwise.co
In the near future, we plan to go further than that by releasing a script that builds the source code locally and computes its hash, then compares that to the hash of the current production signed package and alerts you if they don't match. The intention is to make it easily detectable if we ever sign and deploy code that differs from what's in GitHub, such that any hypothetical "secret" backdoor would need to be hidden in plain sight right in the revision control commit log (which we would expect to eventually be caught by an independent security analyst).