|
|
|
|
|
by 336f5
3921 days ago
|
|
Then use reproducible builds. You inspect the source code, and if it does what it's supposed to, compile it reproducibly, and compare the binary with the official one which has a signature. If they match, then everything is kosher. |
|
I don't know the solution, but the black box approach we have right now I do not like. As a pilot this is a bit weird for me to say because those systems are also completely proprietary as well, full on black box - and not the d/v recording type. And I'm even wondering if that's overdue for a change as well.