Debian must ship reproducible packages

104 points by fanf


fpbgg

This is a good move for security. It might be annoying to transition, but the end result will be higher assurance for Debian Linux users the world over.

SamRW

Can someone please explain the main benefit to a project like Debian? Is it so that we can all have proof that the binaries have not been backdoored? I.e., it reduces the trust required on the maintainers, and reduces the risk of malicious maintainers?

I'm not sceptical, I'm just not 100% sure I understand why Debian is spending so much time on this, I assume making builds reproducible is quite tricky, and fiddly?

ph14nix

Is Debian's idea of reproducibility the same as that of, say, NixOS?