Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

111–112 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#111
post #105

Earlier quoted context omitted.

Can you verify the binaries by reproducing them and comparing hashes? (obviously not of the whole binary but maybe some portion) That would protect the users of those binaries.

Deterministic compilation isn't commonplace yet. I'm not even sure if it's really usable at all yet. Generally, we rely on signed binaries.

So the signature gives you confidence because you trust the signatory?

Re: A Backdoor in Skype for Mac OS X

#112
post #105

Earlier quoted context omitted.

Deterministic compilation isn't commonplace yet. I'm not even sure if it's really usable at all yet. Generally, we rely on signed binaries.

So the signature gives you confidence because you trust the signatory?

Yes, or more specifically, because I trust the keys published by the developers are controlled only by the developers, and because I trust the developers to compile correctly.
Post reply on HN