[Git][reproducible-builds/reproducible-website][master] gothenburg: Add d2-rb-social.md

Bernhard M. Wiedemann (@bmwiedemann-guest) gitlab at salsa.debian.org
Fri Sep 25 08:16:34 UTC 2026



Bernhard M. Wiedemann pushed to branch master at Reproducible Builds / reproducible-website


Commits:
8b3e801b by Bernhard M. Wiedemann at 2026-09-25T10:16:27+02:00
gothenburg: Add d2-rb-social.md

- - - - -


1 changed file:

- + _events/gothenburg2026/agenda/d2-rb-social.md


Changes:

=====================================
_events/gothenburg2026/agenda/d2-rb-social.md
=====================================
@@ -0,0 +1,98 @@
+## social
+
+Android world: Users trust the developer more.
+Open source world: trust in developers is even greater because of the anti-large-corp sentiment.
+
+Is this package really from the developer? 
+- Less people to put trust in.
+- Fdroid's perspective: F-droid checks that it's actually safe/the same, but users don't necessarily share that sentiment.
+
+Have a builder available to verify it, hosted by other people?
+Analogy with Tor nodes hosted by universities, community, ...
+
+Old apps are signed by the developer, Google signs it on top before 2021.
+F-droid started with signing (breaks reproduciblity).
+
+Key management would be simplified if it can be shown that the built APK is directly from the source code.
+"Smentically equivalent"? Can be viewed as integrity being broken.
+
+`.jar` -> compare the `.zip` inside the file.
+Building on different distro's changes the `.zip` structure.
+
+---
+
+Rebuilding something from 30 years ago, there's mechanisms to show the changes are minimal.
+Maintenance vs security? 
+
+What do people care about?
+
+- Security is attractive to us, to a specific group
+- Caching
+- Maintenance may be more attractive to the general public
+- Supply chain autonomy / Software sovereignty
+
+### Security
+
+- Establishing "trust"
+    - Binary matches source
+    - Makes developers less of a target
+      - If people know something is reproducibly built, attackers need to compromise the source rather than the tooling.
+      - Attackers need to affect more to successfully pull it off
+
+### Caching
+
+### Long term maintance
+
+## Why not do RB?
+
+- "If it's not 100% reproducible, it's not worth it"
+- "It's hard"
+    - Not a priority from the start, makes it more painful to do afterwards
+    - Perception of "bit for bit" identical or nothing
+
+- "What's the value?"
+- "Out of my control"
+    - e.g. Tooling
+    - A compiler that doesn't support it
+    - Availability (toolchain, ..., whatever is needed to rebuild it)
+
+- Low priority
+- Long-term cost 
+    - Complexity
+    - Time
+
+
+### How to help
+
+- Education
+- Documentation
+- Soft gatekeeping, personal help
+- Should we embrace AI?
+- Regulation
+
+## Accademia
+
+- Getting into "bit-for-bit" identicality is very far away for scientific research
+
+Some submissions have different criteria:
+
+1. It exists
+2. It builds
+3. It runs
+4. It is reproducible
+
+The incentive for submission of papers contrasts open source.
+
+## Case for "rebuilders"
+
+- A 3-rd party check that shows it has been rebuilt and works.
+
+### Hosting a rebuilder as a 3rd-party
+
+- Independently verify something can be rebuild
+- Community
+    - Allows for those who can't run it to still verify the result
+
+- Fix bugs or security issues
+- Flag build environment discrepancies
+- Help identify mallware



View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/8b3e801b3262b2d00b08b26a3d35a852b88a61da

-- 
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/8b3e801b3262b2d00b08b26a3d35a852b88a61da
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.reproducible-builds.org/pipermail/rb-commits/attachments/20260925/779ec6ca/attachment.htm>


More information about the rb-commits mailing list