guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Preparing the reduced bootstrap tarballs


From: Giovanni Biscuolo
Subject: Re: Preparing the reduced bootstrap tarballs
Date: Mon, 19 Nov 2018 19:54:43 +0100

Hi Jeremiah,

address@hidden writes:

[...]

> and once I finally complete stage0; you would also have the blueprints
> for making the virtual machine in hardware,

so, if I don't get it wrong, every skilled engineer will be able to
build an "almost analogic" (zero bit of software preloaded) computing
machine ad use stage0/mes [1] as the "metre" [2] to calibrate all other
computing machines (thanks to reproducible builds)?

> hand toggle in the bits for the hex0-monitor

the first bit of code have to be "manually" introduced in the machine,
right?
for the lazyer like me, what about a punched card? :-) 

> and have absolute proof that no trusting trust or Nexus
> Intruder Class attacks have occurred in the creation of the binaries.

I didn't know about Nexus Intruder attacks: could you please give me
some links to the relevant bibliography?

> Every issue anyone is willing to bring, I will publicly address until
> all bootstrap roots (even on arbitrary hardware) lead to the proof that
> these binaries are perfectly reproducible and that they only behave in
> the manner explicitly specified by the standards to which they
> conform.

so, having the scientific proof that binary conforms to source, there
will be noo need to trust (the untrastable)

thank you!

Ciao
Giovanni

[2] I still have not fully understood the relationship between stage0
and mes
[1] https://en.m.wikipedia.org/wiki/Metre

-- 
Giovanni Biscuolo

Xelera IT Infrastructures

Attachment: signature.asc
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]