How NixOS and reproducible builds could have detected the xz backdoor for the benefit of all
22 min readIn this article, I showcase a method to leverage reproducible builds to build trust in untrusted release assets. I claim that this method would have detected the 2024 xz backdoor attack.