|
|
|
|
|
by mayakacz
2382 days ago
|
|
Agreed with this statement.
It's a best practice generally to verify all software updates originate from a particular source before applying them in your environment. Most over the wire updates do this.
What's different with Binary Authorization for Borg is that within Google, that last verification step means more than just "came from Google", but "came from Google and went through all previous necessary checks", because of the way the CI/CD system works together. Disclosure: I work at Google and helped write this whitepaper on Binary Authorization for Borg. |
|
I am saying that our solution provides almost the opposite: publicly-verifiable assurance that you are running legitimate binaries, despite being built by automation