Software distribution processes that rely on cryptographic signatures for security are not resilient against targeted backdoors. A software transparency system is presented in which the distributor uses Merkle tree-based logs for software packages. The system further ensures the availability of auditable and attributed source code for all binaries, detecting and warning about irregularities. Scalability of the system for the APT package manager is shown on updates of two years for 25,000 software projects.
«
Software distribution processes that rely on cryptographic signatures for security are not resilient against targeted backdoors. A software transparency system is presented in which the distributor uses Merkle tree-based logs for software packages. The system further ensures the availability of auditable and attributed source code for all binaries, detecting and warning about irregularities. Scalability of the system for the APT package manager is shown on updates of two years for 25,000 softwar...
»