Originally posted by mSparks
View Post
Announcement
Collapse
No announcement yet.
Fedora 41 Approved To Make Package Builds More Reproducible
Collapse
X
-
-
Originally posted by mSparks View Post
PRNG is deterministic, so the basic confusion is just these guys dont know what non deterministic means?
(i.e. As far as users who want to reproduce builds without being domain experts are concerned, a build hash that takes a timestamp as input for some reason is indistinguishable from a true random number being embedded in the code.)
In essence, they're calling it non-determinism because, in this context, it's most useful to apply "guilty until proven innocent" rules and say that behaviour is non-deterministic until it can "cite its sources". (Basically, similar to how we apply sandboxing to applications because, in the world of security, it makes sense to assume that something is insecure until proven otherwise.)
TL;DR: They know what non-determinism is. They're using it in a Clarke's Third Law-esque "sufficiently obscured side-channel inputs are indistinguishable from random inputs as far as the relevant demographics are concerned" sense.Last edited by ssokolow; 10 May 2024, 04:53 PM.
Comment
-
Originally posted by mSparks View PostAgreed.
How was this ever a thing?
- Likes 1
Comment
Comment