Spyke

Replies

Comment on

How can I prove that a downloadable executable is built from the published source?

I don't know whether github actions output can be tampered with by you, but the only actually reliable way (that I know of) to prove that your binaries correspond to a certain state of the sourcecode is to support reproducible builds (See e.g. https://reproducible-builds.org/).

All other methods require trust (in either the developer or w.r.t. github actions towards github).

The drawback is of course, that to verify whether your binaries are good, someone needs to rebuild the software, but it is a good tool to build and maintain trust in your signed binaries, especially if they deal with sensitive information like private keys.

privacy

Comment on

U2F/FIDO2 on Degoogled phone

Basically, yes. IIRC the FIDO/U2F handling is implemented in google libs.

They are however re-implemented in microG: https://github.com/microg/GmsCore/wiki/Implementation-Status, so if you are open to using that it should work with apps using the corresponding google client libraries.

I have used Firefox on Lineage/microG and tested FIDO2 there, it does NOT work with Fennec as that does not include the required client side libraries.

wordle

Comment on

Wordle #1000 - Fri 15 March 2024

Wordle 1,000 🎉 4/6*

🟨🟨⬛⬛⬛
⬛🟨🟨⬛🟨
🟨⬛🟨🟨⬛
🟩🟩🟩🟩🟩

Today wordle tried to push an account on me to see my stats... the enshittification is creeping. Reloading fixed it. For now. I will not make an account for a morning puzzle.