Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>It would need to be repeatably build-able with the result matching the signature of the default blob.

Huh? You can most certainly verify if an unsigned blob matches a signed blob.



(?) Obviously, but building a bit-by-bit identical compiler output is moderately hard.


I must've misunderstood you then.

Anyway, surely "This would not increase trust" is a bit of an overly strong statement. Even if AMD didn't release reproducible build instructions, having the source code would still make it significantly easier to detect AMD shipping different (compiled) code.

But yeah, open sourcing the PSP without reproducible builds would be a little silly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: