Skip to content

Comment on Deterministic, bit-identical and/or verifiable Linux buildsparent

Comments

Depending on the browser component model, could you hash individual binary components? Over time, "base" components could stabilize in the same manner as long-term-support Linux kernels, with surgical patches for security fixes. I don't know how practical this would be with the component models for Firefox and Chromium.

Sounds somewhat reasonable; though, some long term support Linux installations were vulnerable to Heartbleed.

And, especially with how far reaching some of the features of modern browsers are, the surface area for attacks is growing rather large.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.