!LemuOOvbWqRXodtSsw:nixos.org

NixOS Reproducible Builds

545 Members
Report: https://reproducible.nixos.org Project progress: https://github.com/orgs/NixOS/projects/30124 Servers

Load older messages


SenderMessageTime
7 Jun 2022
@toonn:matrix.orgtoonn Majority vote? 09:29:26
@j-k:matrix.orgj-kits a central db with copies, or do you mean trustix?09:29:49
@toonn:matrix.orgtoonn No, Sigstore. How are discrepancies across copies resolved? 09:30:23
@toonn:matrix.orgtoonn Doesn't it run into the voting is basically free problem? 09:30:40
@raboof:matrix.orgraboof
In reply to @toonn:matrix.org
rnhmjoj: This blog post touches on why they don't consider a blockchain suitable for this, https://www.tweag.io/blog/2022-02-03-trustix-voting/#blockchains
also see https://www.tweag.io/blog/2022-01-14-trustix-trees/ - some people would, loosely speaking, call this Certificate Transparency-like approach a 'blockchain' as well (especially when looking for funding 😄), but it's a lot more reasonable for this use case
09:31:58
@j-k:matrix.orgj-k
In reply to @toonn:matrix.org
No, Sigstore. How are discrepancies across copies resolved?
IDK if they've done much on discrepancies across copies. I think it's a "when it happens we'll discuss it" type thing 🙃
10:05:38
@toonn:matrix.orgtoonn : s I've only seen the "leave the hard problems for later" approach work once and that was with Matrix e2ee. 10:39:23
@raboof:matrix.orgraboofin the reproducible builds context I'd say discrepancies across copies fundamentally need human intervention in any case, to judge whether it is accidental (and the indeterminism needs to be fixed) or a breach (in which case trust should be revoked from whoever was breached, until they fix things)10:44:24
@toonn:matrix.orgtoonn That's fair. 10:45:27
@foxboron:archlinux.orgFoxboron
In reply to @toonn:matrix.org
No, Sigstore. How are discrepancies across copies resolved?
That's the implementation details for the client. Transparency logs themselves do not solve this problem. They just record stuff and allow you to verify if the entry on the log has been tampered with or not. The same applies for trustix
11:01:24
@foxboron:archlinux.orgFoxboronEveryone that wants a Blockchain to solve these problems usually just want a transparency log 🙃 it's the number one question i get when i explain these things11:03:21
@foxboron:archlinux.orgFoxboronSigstore *also* published a post on why blockchains are not suitable. https://blog.sigstore.dev/sigstore-blockchain-vs-transparency-logs-d673ea41a9be11:07:38
@foxboron:archlinux.orgFoxboron(someone also implemented sigstore ontop of ethereum smart contracts, but let's not talk about that)11:08:14
@foxboron:archlinux.orgFoxboron Also lol. Did adisbladis steal the pun i made for my master thesis :)? 11:09:35
@adis:blad.isadisbladis
In reply to @foxboron:archlinux.org
Also lol. Did adisbladis steal the pun i made for my master thesis :)?
Hm?
11:10:09
@adis:blad.isadisbladis
In reply to @foxboron:archlinux.org
(someone also implemented sigstore ontop of ethereum smart contracts, but let's not talk about that)
The first PoC of Trustix was an ethereum smart contract, but I quickly realised that the economics of blockchains don't make sense for this application
11:10:59
@foxboron:archlinux.orgFoxboron
In reply to @adis:blad.is
Hm?
I have the same pun in my thesis. "Break a log: good things come in trees" :p i found it funny
11:12:27
@adis:blad.isadisbladis
In reply to @foxboron:archlinux.org
I have the same pun in my thesis. "Break a log: good things come in trees" :p i found it funny
Maybe I stole it without even realising ^_^
11:12:53
@foxboron:archlinux.orgFoxboronIt's a great pun :) No worries11:13:13
@foxboron:archlinux.orgFoxboron adisbladis: also, there is a general standardization effort (SCITT) to have transparency logs used for supply chain security. I'm not sure how interesting it is but a meeting next week. https://blog.sigstore.dev/sigstore-blockchain-vs-transparency-logs-d673ea41a9be 11:16:54
@foxboron:archlinux.orgFoxboronArgh. Copy-paste failure.11:17:21
@tinybronca:sibnsk.net@tinybronca:sibnsk.netIs there a reason why the website does not show build reproducability status?11:17:56
@tinybronca:sibnsk.net@tinybronca:sibnsk.netOr is there some online resource to check this?11:17:57
@foxboron:archlinux.orgFoxboronhttps://mailarchive.ietf.org/arch/msg/scitt/drt9mk3UCJ-x6-_n8jLh_nr9Gb0/ https://github.com/ietf-scitt11:17:57
@tinybronca:sibnsk.net@tinybronca:sibnsk.net(that I don't know)11:17:58
@tinybronca:sibnsk.net@tinybronca:sibnsk.net
@tinybronca:sibnsk.net
Is there a reason why the website does not show build reproducability status?
🤔❓
11:17:59
@adis:blad.isadisbladis
In reply to @foxboron:archlinux.org
https://mailarchive.ietf.org/arch/msg/scitt/drt9mk3UCJ-x6-_n8jLh_nr9Gb0/
https://github.com/ietf-scitt
A bit of an awkward time for me :/
11:19:38
@adis:blad.isadisbladisIt's at midnight here11:20:03
@foxboron:archlinux.orgFoxboronAwh :/ 11:22:08
@j-k:matrix.orgj-kdoes one need to sign up for ietf datatracker to participate?11:33:02

Show newer messages


Back to Room ListRoom Version: 6