|
|
|
|
|
by taeric
4354 days ago
|
|
That sounds tangential. The point is if two people build the same thing, they should be able to compare their builds to see if they are truly the same. If not, the argument is that one of them has a "tampered" environment. In other words, if you don't know your compiled binary is the same as the distributed binary, you have no reason to think yours does not have a vulnerability added by the toolchain. Unless I'm the one that is misunderstanding, of course. :) |
|