From Newsgroup: comp.lang.forth
anton@mips.complang.tuwien.ac.at (Anton Ertl) writes:
you get the snapshot from <https://www.complang.tuwien.ac.at/forth/gforth/Snapshots/>, which is
secured with https, and the signature comes from
<https://savannah.gnu.org/>, also secured with https, so an attack
scenario that subverts all that is interesting. The easiest way
probably would be to break into Bernd Paysan's computer where he
builds and signs Gforth, but then a trusted signature does not help.
Generally speaking, so-called rCLreproducible buildsrCY are a potential solution to this problemrCerCorCethey do not prevent back doors from being introduced into the source code, but if there is no back door in the
source code, they will detect any attempt to introduce back doors into
the executable code, because builds on different machines will not match byte-for-byte. (Unless all of the build machines have been subverted by
the same attacker.)
Debian is currently succeeding in building GForth 0.7.3 reproducibly: <
https://reproduce.debian.net/amd64/forky.html#gforth>
Kragen
--- Synchronet 3.22a-Linux NewsLink 1.2