Tavis Ormandy of Google Project Zero wrote a very good debunking of this supposed security benefit of reproducible builds: https://blog.cmpxchg8b.com/2020/07/you-dont-need-reproducibl...
Tavis Ormandy of Google Project Zero wrote a very good debunking of this supposed security benefit of reproducible builds: https://blog.cmpxchg8b.com/2020/07/you-dont-need-reproducibl...
I doubt Tavis is saying that builds should not be reproducible; just that it is not going to provide security on it's own in a trivial manner. I'd argue that reproducibility can help create secure systems with properties otherwise unobtainable (or difficult).
My own view is that all of supply chain security is somewhat of a red herring anyway. I don’t want to have to trust software vendors at all, whether I think they may have been hacked or not. I shouldn’t have to trust log4j or any other legitimate dependency. And I shouldn’t have to audit the source code (or delegate that) to find out if I should trust it. We run all software with far too many privileges by default. Kate Sills at Agoric had a great article about this a few years back (Medium, sorry): https://medium.com/agoric/pola-would-have-prevented-the-even...