Kettle: Attested builds for verifiable software provenance

3 points by badcryptobitch


k749gtnc9l3w

Wasn't another submission recently explaining how modern TEEs are not in fact promising that much against an attacker with physical access and a well-equipped (but not exclusive-to-nation-state level) lab?

CluEleSsUK

I saw a call for Debian to ship reproducible builds - this could be a nice stepping stone or alternative path