Hacker News new | past | comments | ask | show | jobs | submit login

Deterministic compilation isn't commonplace yet. I'm not even sure if it's really usable at all yet.

Generally, we rely on signed binaries.




So the signature gives you confidence because you trust the signatory?


Yes, or more specifically, because I trust the keys published by the developers are controlled only by the developers, and because I trust the developers to compile correctly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: