Hacker News new | ask | show | jobs
by fsflover 1934 days ago
But you cannot verify the source code and binary of the server or set up your own independent one, so reproducible builds don't help here.
1 comments

That's true, and in that sense it doesn't really matter if they publish the server source or not (although they really should continue to do so). What does matter is that the client was designed with a possible malicious server in mind so you don't have to trust the code the server is running.