|
|
|
|
|
by can16358p
308 days ago
|
|
Okay I don't have much information about this whole attestation flow and one question boggles my mind. If someone can explain this in simple terms, I'd be thankful: The post says build the repo and get the fingerprint, which is fine. Then it says compare it to the fingerprint that vp.net reports. My question is: how do I verify the server is reporting the fingerprint of the actual running code, and not just returning the (publicly available) fingerprint that we get result of building the code in the first place? |
|