On Wed, Aug 27, 2008 at 5:52 AM, Bojan Smojver <bojan rexursive com> wrote:
Well, just because we base our build comparisons right now on something as crude
as raw checksums, doesn't mean this has to be like that forever. We may find
ways of comparing builds differently to determine if they were compromised, by
explicitly excluding well known differences within binaries.
How about you back up and just work on this very specific problem of
deterministically doing build comparisons across disparate build
systems ..before we even begin to discuss how a multiple sigantory
process which relies on that.