Hacker News new | ask | show | jobs
by sneak 1750 days ago
As I mentioned, this is irrelevant one second after it's published.
1 comments

If they tie a hash of the software to the report, then you can verify the software is the same.

Not sure how to handle updates later though. What level of udpates would require an entirely new audit?

But how do you verify the backend code and infrastructure?

Thats the most important question for a VPN.

The audit commoner is referring to is of their backend infrastructure, not their published software.