True. This is why all client side source code will be released and reproducible builds offered on platforms that support it.
If you don't know what code you're running, yeah you're screwed either way.
True. This is why all client side source code will be released and reproducible builds offered on platforms that support it.
If you don't know what code you're running, yeah you're screwed either way.
Look- the point is, you will go down a endless rabbithole of trying to appease everyone with "bulletproof" security. And the more you go, the more functionality and usefulness you will give up.
The best solution is to be realistic and not make defacto claims. Even things like TOR, which have been open source and audited from day one have had serious issues, and I am sure many TOR developers parroted the "you cant be tracked using us" only to have exploits and code issues pop up multiple times.
Nixpkgs please! It's the most successful reproducibility experiment I know of.
Fun fact: all of the current website's infra is NixOS-based
Fun fact #2: I overhauled Bitcoin Core's reproducible build system to use Guix (a Nix-inspired functional package manager)
All the nix deployment tools had too much magic and broke, but nixos-rebuild always works and it's part of Nix!
Disko was great for bootstrapping servers: https://github.com/nix-community/disko