> You can already verify that a
> toolchain wasn't backdoored )
> today
How, exactly?
If we both compiled hello.c (a prototypical hello world program), and exchanged binaries; how would you verify my build wasn't malicious?
How, exactly?
If we both compiled hello.c (a prototypical hello world program), and exchanged binaries; how would you verify my build wasn't malicious?
That does require reproducible builds, but here is how to do it without reproducible builds:
Take the trusted source code, then compile it to make a trusted binary. Now put the untrusted binary in the trash, cause you already have a trusted binary :)